Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9483

Опубликовано: 13 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jqueryform:php_formmail_generator:-:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00615
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.

EPSS

Процентиль: 69%
0.00615
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-502
CWE-502