Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exponent | Exponent | 0.94 (including) | 0.94 (including) |
Exponent | Exponent | 0.95 (including) | 0.95 (including) |
Exponent | Exponent | 0.96.1 (including) | 0.96.1 (including) |
Exponent | Exponent | 0.96.3 (including) | 0.96.3 (including) |
Exponent | Exponent | 0.96.4 (including) | 0.96.4 (including) |