ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-11 19:16
Updated : 2026-06-17 02:32
NVD link : CVE-2019-25480
Mitre link : CVE-2019-25480
CVE.ORG link : CVE-2019-25480
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
