Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q99f-3fh3-fpw2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.

EPSS

Процентиль: 85%
0.02522
Низкий

Связанные уязвимости

nvd
около 20 лет назад

Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.

EPSS

Процентиль: 85%
0.02522
Низкий