Описание
PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.
Ссылки
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:phpshop:phpshop:0.6.1b:*:*:*:*:*:*:*
cpe:2.3:a:phpshop:phpshop:0.7:*:*:*:*:*:*:*
cpe:2.3:a:phpshop:phpshop:0.7.1:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00968
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.
EPSS
Процентиль: 76%
0.00968
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other