CVE-2018-19457

Publication date

2018-11-22 20:00:00

Family

mitre

State

PUBLISHED

Description

Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.