Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j3q-vc9h-xvcv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

EPSS

Процентиль: 66%
0.01233
Низкий

Связанные уязвимости

nvd
около 19 лет назад

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

EPSS

Процентиль: 66%
0.01233
Низкий