Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxf9-rgcc-942c

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

EPSS

Процентиль: 78%
0.01172
Низкий

8.8 High

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 8.8
nvd
почти 24 года назад

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
debian
почти 24 года назад

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users ...

EPSS

Процентиль: 78%
0.01172
Низкий

8.8 High

CVSS3

Дефекты

CWE-665