Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24cw-v655-38cr

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.

x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.

EPSS

Процентиль: 69%
0.00622
Низкий

Связанные уязвимости

nvd
больше 22 лет назад

x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.

EPSS

Процентиль: 69%
0.00622
Низкий