Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j3q-vc9h-xvcv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

EPSS

Процентиль: 68%
0.00574
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

EPSS

Процентиль: 68%
0.00574
Низкий