VYPR
Critical severity9.8NVD Advisory· Published Jun 2, 2017· Updated May 13, 2026

CVE-2017-9364

CVE-2017-9364

Description

Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.