Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f23-cwjx-x2rh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.

Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.

EPSS

Процентиль: 93%
0.10615
Средний

Связанные уязвимости

nvd
почти 20 лет назад

Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.

EPSS

Процентиль: 93%
0.10615
Средний