Описание
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:luocms_project:luocms:2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00335
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
EPSS
Процентиль: 56%
0.00335
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-863