givanz VvvebJs
cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*
- <= 1.7.4
A vulnerability in VvvebJs version 1.7.2 allows for unrestricted file upload, enabling the upload of malicious files that could lead to remote code execution.
Exploitation of this vulnerability allows for unrestricted file uploads, which can be used to execute malicious code on the server.
To reproduce this vulnerability, upload a file through the application's file upload feature, such as 'upload.php'. The uploaded file can be a PHP file disguised with a different extension, like '.php16'. After uploading, the file can be accessed via the web server, potentially executing any embedded code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.