Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-update | Php-update | * | 2.7 (including) |