class.upload.php in verot.net class.upload prior to 1.0.3 and 2.x prior to 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
verot project verot |
||
getk2 k2 |