Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4x8-8wjv-gmfj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

EPSS

Процентиль: 75%
0.00898
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

EPSS

Процентиль: 75%
0.00898
Низкий