VYPR
High severity7.2NVD Advisory· Published May 24, 2019· Updated Jun 17, 2026

CVE-2016-10751

CVE-2016-10751

Description

osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Osclass/Osclass2 versions
    cpe:2.3:a:osclass:osclass:3.6.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:osclass:osclass:3.6.1:*:*:*:*:*:*:*
    • (no CPE)range: =3.6.1
  • osClass/osClassdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.