Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3xg-2p49-9cfp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

EPSS

Процентиль: 99%
0.79642
Высокий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 13 лет назад

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

EPSS

Процентиль: 99%
0.79642
Высокий

Дефекты

CWE-94