Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2019-19634
- EPSS 4.19%
- Veröffentlicht 17.12.2019 18:15:14
- Zuletzt bearbeitet 26.06.2026 14:53:03
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
9.8
CVE-2019-19576
- EPSS 26.38%
- Veröffentlicht 04.12.2019 18:15:16
- Zuletzt bearbeitet 26.06.2026 14:53:03
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
7.5
CVE-2018-7482
- EPSS 2.31%
- Veröffentlicht 28.02.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:12
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The...
1