Files
CVEs-PoC/2018/CVE-2018-20127.md
T
2025-09-29 21:09:30 +02:00

772 B

CVE-2018-20127

Description

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension and an extra '.' character, because (for example) "php" is blocked but path=F:/1.phP. succeeds.

POC

Reference

No PoCs from references.

Github