Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17098

Опубликовано: 02 янв. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by in a login request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gps-server:gps_tracking_software:*:*:*:*:*:*:*:*
Версия до 3.0 (включая)

EPSS

Процентиль: 97%
0.31242
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

EPSS

Процентиль: 97%
0.31242
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94