Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c33-67p8-93vq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.

modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.

EPSS

Процентиль: 80%
0.01318
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 16 лет назад

modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.

EPSS

Процентиль: 80%
0.01318
Низкий

Дефекты

CWE-94