Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmg6-rx53-j5wr

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

EPSS

Процентиль: 97%
0.42075
Средний

7.5 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.5
nvd
почти 8 лет назад

Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

EPSS

Процентиль: 97%
0.42075
Средний

7.5 High

CVSS3

Дефекты

CWE-78