Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56jv-hmch-qm6c

Опубликовано: 11 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

EPSS

Процентиль: 91%
0.06884
Низкий

10 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
nvd
больше 3 лет назад

CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

EPSS

Процентиль: 91%
0.06884
Низкий

10 Critical

CVSS3

Дефекты

CWE-434