Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv2x-75x9-84vr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

EPSS

Процентиль: 80%
0.01348
Низкий

Дефекты

CWE-78

Связанные уязвимости

nvd
больше 14 лет назад

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

EPSS

Процентиль: 80%
0.01348
Низкий

Дефекты

CWE-78