Medium
CVSS 5.0
Overview
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.
Unrestricted file upload vulnerability in The Address Book 1.04e validates the C...
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: