Vulnerabilities > Logicspice

DATE CVE VULNERABILITY TITLE RISK
2018-11-22 CVE-2018-19457 Unrestricted Upload of File with Dangerous Type vulnerability in Logicspice FAQ Script 2.9.7
Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.
network
low complexity
logicspice CWE-434
6.5