Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18934

Опубликовано: 05 нояб. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:popojicms:popojicms:2.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00129
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.

EPSS

Процентиль: 33%
0.00129
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-352