Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing .php.rar or other multiple extensions that include .php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Discuz | Crosscom_olicom | * | 4.0_rc4 (including) |