Search Results (Refine Search)
- CPE Product Version: cpe:/a:ultimatefosters:ultimatepos:2.5
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2018-17139 |
UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type. Published: September 17, 2018; 2:29:00 AM -0400 |
V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |