Логотип exploitDog
bind:CVE-2020-4043
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-4043

Количество 2

Количество 2

nvd логотип

CVE-2020-4043

больше 5 лет назад

phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-qr95-4mq5-r3fh

больше 5 лет назад

Phar unserialization vulnerability in phpMussel

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-4043

phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.

CVSS3: 7.7
2%
Низкий
больше 5 лет назад
github логотип
GHSA-qr95-4mq5-r3fh

Phar unserialization vulnerability in phpMussel

CVSS3: 7.7
2%
Низкий
больше 5 лет назад

Уязвимостей на страницу