Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x54g-9ph7-cxpv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

EPSS

Процентиль: 89%
0.04892
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

EPSS

Процентиль: 89%
0.04892
Низкий