Описание
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.
Ссылки
- ExploitVendor Advisory
- PatchVendor Advisory
- Exploit
- PatchURL Repurposed
- Exploit
- ExploitVendor Advisory
- PatchVendor Advisory
- Exploit
- PatchURL Repurposed
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:phpx:phpx:3.5:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.6:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.7:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.8:*:*:*:*:*:*:*
cpe:2.3:a:phpx:phpx:3.5.9:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.03088
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.
EPSS
Процентиль: 86%
0.03088
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other