Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4rg-9v64-h6w4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.

EPSS

Процентиль: 99%
0.84053
Высокий

Дефекты

CWE-94

Связанные уязвимости

nvd
около 14 лет назад

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.

debian
около 14 лет назад

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before ...

EPSS

Процентиль: 99%
0.84053
Высокий

Дефекты

CWE-94