#VU20057 Arbitrary file upload in cformsII - CVE-2014-9473
Published: August 12, 2019 / Updated: April 7, 2020
cformsII
Oliver Seidel, Bastian Germann
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of user-supplied input when uploading files in "lib_nonajax.php" script. A remote attacker can upload and execute arbitrary file on the server via the the "cf_uploadfile2[]" parameter.