Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33gq-cgfx-f6m6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

EPSS

Процентиль: 92%
0.08254
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
около 18 лет назад

Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

EPSS

Процентиль: 92%
0.08254
Низкий

Дефекты

CWE-94