Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vc8-f4x6-cg96

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

EPSS

Процентиль: 89%
0.04517
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

EPSS

Процентиль: 89%
0.04517
Низкий

Дефекты

CWE-77