UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moniwiki | Moniwiki | 1.0.8 (including) | 1.0.8 (including) |
Moniwiki | Moniwiki | 1.0.9 (including) | 1.0.9 (including) |
Moniwiki | Moniwiki | 1.0.9.1 (including) | 1.0.9.1 (including) |