Record summary

CVE-2019-19576 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.0.3 · Fixed in 1.0.3affected
2.0.0 to < 2.0.4 · Fixed in 2.0.4affected

Proofs of concept

2

Catalogued exploits

ExploitDBVerot 2.0.3 - Remote Code ExecutionExploitDB exploitby Jinny RamsmarkNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubjra89/CVE-2019-19576Repository PoCby jra89Stars: 12Not analyzed7 files

265.4 KiB

GitHub

PoC details

References

12