Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3mr-q96r-37v4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

phpBB Remote Code Execution

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

Пакеты

Наименование

phpbb/phpbb

composer
Затронутые версииВерсия исправления

< 3.2.4

3.2.4

EPSS

Процентиль: 94%
0.14464
Средний

7.2 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 7 лет назад

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

CVSS3: 7.2
nvd
около 7 лет назад

Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

CVSS3: 7.2
debian
около 7 лет назад

Passing an absolute path to a file_exists check in phpBB before 3.2.4 ...

EPSS

Процентиль: 94%
0.14464
Средний

7.2 High

CVSS3

Дефекты

CWE-502