Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp9q-x4mx-9j95

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

EPSS

Процентиль: 98%
0.38301
Средний

Связанные уязвимости

nvd
почти 24 года назад

Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.

EPSS

Процентиль: 98%
0.38301
Средний