Описание
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter.
Ссылки
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:esyndicat:esyndicat_directory:1.2:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00741
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter.
EPSS
Процентиль: 72%
0.00741
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other