Arbitrary Code Execution via Directory Traversal in Kayson Group Ltd. phpGrid

Arbitrary Code Execution via Directory Traversal in Kayson Group Ltd. phpGrid

CVE-2017-10665 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name.

Learn more about our Web Application Penetration Testing UK.