Field Assessment
AI analysis pending.
CVE
CVE-2002-1841
Severity
MEDIUM
CVSS
5
EPSS
2.14%
Original Filing — NVD Description
The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.