AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-11756

HIGH · CVSS 7 EPSS 0.71%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-07-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-11756
Severity
HIGH
CVSS
7
EPSS
0.71%

Original NVD Description

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.