CVE Vulnerabilities

CVE-2011-1329

Published: May 31, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.

Affected Software

NameVendorStart VersionEnd Version
WalrackWalrus_digit1.0.1 (including)1.0.1 (including)
WalrackWalrus_digit1.1.1 (including)1.1.1 (including)
WalrackWalrus_digit1.1.2 (including)1.1.2 (including)
WalrackWalrus_digit1.1.3 (including)1.1.3 (including)
WalrackWalrus_digit1.1.4 (including)1.1.4 (including)
WalrackWalrus_digit1.1.5 (including)1.1.5 (including)
WalrackWalrus_digit1.1.6 (including)1.1.6 (including)
WalrackWalrus_digit1.1.7 (including)1.1.7 (including)
WalrackWalrus_digit1.1.8 (including)1.1.8 (including)
WalrackWalrus_digit2.0.1 (including)2.0.1 (including)
WalrackWalrus_digit2.0.2 (including)2.0.2 (including)
WalrackWalrus_digit2.0.3 (including)2.0.3 (including)
WalrackWalrus_digit2.0.4 (including)2.0.4 (including)
WalrackWalrus_digit2.0.5 (including)2.0.5 (including)
WalrackWalrus_digit2.0.6 (including)2.0.6 (including)

References