655
VMScore

CVE-2018-18924

Published: 04/11/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The image-upload feature in ProjeQtOr 7.2.5 allows remote malicious users to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

projeqtor projeqtor

Exploits

# Exploit Title: ProjeQtOr Project Management Tool 725 - Remote Code Execution # Date: 2018-10-22 # Exploit Author: Özkan Mustafa Akkuş (AkkuS) # Contact: pentestcomtr # Vendor Homepage: wwwprojeqtororg # Software Link: sourceforgenet/projects/projectorria/files/projeqtorV725zip/download # Version: v725 # Categ ...