Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp9q-x4mx-9j95

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

EPSS

Процентиль: 95%
0.20915
Средний

Связанные уязвимости

nvd
больше 23 лет назад

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

EPSS

Процентиль: 95%
0.20915
Средний