Описание
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.3 (включая)
cpe:2.3:a:codiad:codiad:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.41511
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
EPSS
Процентиль: 97%
0.41511
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78