Описание
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.
Ссылки
- ExploitPatchVendor Advisory
- Patch
- Exploit
- ExploitPatch
- ExploitPatchVendor Advisory
- Patch
- Exploit
- ExploitPatch
Уязвимые конфигурации
Конфигурация 1Версия до 3.9.8.4 (включая)
Одно из
cpe:2.3:a:hamweather:hamweather:*:*:*:*:*:*:*:*
cpe:2.3:a:hamweather:hamweather:3.9.8.3:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04517
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.
EPSS
Процентиль: 89%
0.04517
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other