Vulnerability Description
In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Earcms | Ear Music | <= 4.1 |
Related Weaknesses (CWE)
References
- https://lncken.cn/?p=359Third Party Advisory
- https://lncken.cn/?p=359Third Party Advisory
FAQ
What is CVE-2017-11756?
CVE-2017-11756 is a vulnerability with a CVSS score of 7.0 (HIGH). In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a...
How severe is CVE-2017-11756?
CVE-2017-11756 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11756?
Check the references section above for vendor advisories and patch information. Affected products include: Earcms Ear Music.