Critical severity9.8NVD Advisory· Published Apr 11, 2017· Updated May 13, 2026
CVE-2017-7695
CVE-2017-7695
Description
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/bigtreecms/BigTree-CMS/commit/8cf4212ea40e1b843e1aecf4b24681b0964ec04cnvdPatch
- github.com/bigtreecms/BigTree-CMS/issues/276nvdIssue TrackingPatch
- www.math1as.com/bigtree_upload.txtnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.