Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp9g-rcxv-hwmh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.

include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.

EPSS

Процентиль: 69%
0.00596
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.

EPSS

Процентиль: 69%
0.00596
Низкий