Описание
Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.
Ссылки
- PatchVendor Advisory
- Exploit
- Exploit
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:zeroboard:zeroboard:4.1_pl2:*:*:*:*:*:*:*
cpe:2.3:a:zeroboard:zeroboard:4.1_pl3:*:*:*:*:*:*:*
cpe:2.3:a:zeroboard:zeroboard:4.1_pl4:*:*:*:*:*:*:*
cpe:2.3:a:zeroboard:zeroboard:4.1_pl5:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05154
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.
EPSS
Процентиль: 90%
0.05154
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other