3 ms·
It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.
by nieve 2y ago
It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.
- out_of_protocol 2y agoDoes this work with .pdf files? i.e. attacker uploads evil.pdf
- llimllib 2y agoyes, also with .eps files
- worthless-trash 2y agoThats.. in bad faith. If thats the qualification for "remote" then you can say that every attack is remote and it clearly isnt.