关于 CVE-2010-0390 的漏洞信息

1. 漏洞描述
From NVD
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
From 神龙GPT (AIGC)
在PHP F1 Max的Image Uploader 1.0中,maxImageUpload/index.php文件的无限制文件上传漏洞,当Apache未配置处理具有pjpeg或jpeg扩展名的文件的MIME类型时,允许远程攻击者通过上传带有pjpeg或jpeg扩展名的文件,然后通过直接向原始文件发送请求来执行任意代码。注意:其中的某些细节是从第三方信息获取的。
2. 漏洞评分(CVSS)
From NVD
NVD 暂无评分
From 神龙GPT (AIGC)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
3. 漏洞类别
From NVD
NVD 暂无漏洞类别信息
From 神龙GPT (AIGC)
神龙GPT 暂无漏洞类别信息(请耐心等待)
Reference