"value":"Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. NOTE: some of these details are obtained from third party information."
},
{
"lang":"es",
"value":"Vulnerabilidad de subida no restringida de ficheros en upload.php en BTS-GI Read excel v1.1, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n al subir un fichero con una extensi\u00f3n ejecutable, accediendo posteriormente mediante una petici\u00f3n directa del fichero en un direcorio no especificado. NOTE: algunos de estos detalles se han obtenido de terceros."