CVE-2017-1000119 EXPLOIT
7.2
HIGH · CVSS 3.0 · EPSS 61.3% (pctl 99)
Patch early
A public exploit exists.
Description
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
Scoring
| CVSS | 7.2 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 61.35% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-05 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| octobercms | october |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | October CMS - Upload Protection Bypass Code Execution (Metasploit) | 2019-09-10 |
References
→ the Explorer · watch your stack · NVD