Описание
Codiad Vulnerable to Shell Command Injection
components/filemanager/class.filemanager.php in Codiad before 2.8.3 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-11366
- https://github.com/Codiad/Codiad/issues/1011
- https://github.com/Codiad/Codiad/pull/1013
- https://github.com/Codiad/Codiad/pull/1013/commits/b3645b4c6718cef6de7003f41aafe7bfcc0395d1
- https://github.com/Codiad/Codiad/commit/ca5089eeba42d16ce3a7f86be628ac7750780111
- http://www.jianshu.com/p/41ac7ac2a7af
Пакеты
Наименование
codiad/codiad
composer
Затронутые версииВерсия исправления
< 2.8.3
2.8.3
Связанные уязвимости
CVSS3: 9.8
nvd
больше 8 лет назад
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.