CVE-2018-9206
קריטית 9.8
תיאור (מקור, אנגלית)
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-18/8/2026
- CWE
- CWE-434
מוצרים מושפעים
jquery_file_upload_project: jquery file upload
קישורים
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
- http://www.vapidlabs.com/advisory.php?v=204 ExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9136 ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/45790/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46182/ ExploitThird Party AdvisoryVDB Entry
- http://www.vapidlabs.com/advisory.php?v=204 ExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9136 ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/45790/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46182/ ExploitThird Party AdvisoryVDB Entry