Описание
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
Ссылки
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.7.4:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06884
Низкий
10 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 10
github
больше 3 лет назад
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
EPSS
Процентиль: 91%
0.06884
Низкий
10 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-434