Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qh9-p9x6-57f8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

EPSS

Процентиль: 75%
0.00879
Низкий

7.5 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

EPSS

Процентиль: 75%
0.00879
Низкий

7.5 High

CVSS3

Дефекты

CWE-94