Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3640

Опубликовано: 21 июл. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 6
EPSS Низкий

Описание

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpmybackuppro:phpmybackuppro:*:*:*:*:*:*:*:*
Версия до 2.5 (включая)

EPSS

Процентиль: 75%
0.00879
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

EPSS

Процентиль: 75%
0.00879
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-94