Описание
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
Ссылки
- Vendor Advisory
- Exploit
- Exploit
- Vendor Advisory
- Vendor Advisory
- Exploit
- Exploit
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.9 (включая)
cpe:2.3:a:lan_management_system:lan_management_system:*:*:vala:*:*:*:*:*
EPSS
Процентиль: 91%
0.06251
Низкий
10 Critical
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
почти 4 года назад
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
EPSS
Процентиль: 91%
0.06251
Низкий
10 Critical
CVSS2
Дефекты
CWE-94