Skip to content

CVE-2014-2223

Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.1044 (10.4%)
Percentil: 93.3%
EPSS: 2026-05-06

Afecta

plogger:plogger

Descripción técnica

Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.

Publicada: 11/9/2014, 14:16:04
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo