vendor:
by:
Stefan Esser
5.5
CVSS
MEDIUM
Remote File Inclusion
22
CWE
Product Name:
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
PHP ext/filter FDF POST Filter Bypass Exploit
This PHP exploit allows an attacker to bypass the ext/filter FDF POST filter and execute remote code. It works by creating a malicious FDF file and sending it to a target URL.
Mitigation:
To mitigate this vulnerability, it is recommended to ensure that the ext/filter FDF POST filter is properly configured and to keep PHP updated to the latest version.