ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Reviewpost_php_pro | Photopost | * | 2.5.1 (including) |
Reviewpost_php_pro | Photopost | 1.0.2 (including) | 1.0.2 (including) |
Reviewpost_php_pro | Photopost | 2.5 (including) | 2.5 (including) |