Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25c5-9pxc-899f

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

EPSS

Процентиль: 86%
0.02842
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 19 лет назад

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

EPSS

Процентиль: 86%
0.02842
Низкий

Дефекты

CWE-20