An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
{
"cpe": [
"cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*",
"cpe:2.3:a:pluck-cms:pluck:4.7.7:dev1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.7.7"
},
{
"introduced": "4.7.7-dev1"
},
{
"last_affected": "4.7.7-dev1"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}