Vulnerabilities > Fengoffice > Feng Office > 3.7.0.5

DATE CVE VULNERABILITY TITLE RISK
2019-03-07 CVE-2019-9623 Unrestricted Upload of File with Dangerous Type vulnerability in Fengoffice Feng Office 3.7.0.5
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
network
low complexity
fengoffice CWE-434
7.5