Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2016-10752 - Vulnerability Database

Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2016-10752

Critical
Reference: CVE-2016-10752
Title: Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability
Overview:

serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename as demonstrated by quotphpquot as a filename.