Логотип exploitDog
bind:CVE-2017-17098
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-17098

Количество 2

Количество 2

nvd логотип

CVE-2017-17098

около 8 лет назад

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-pmxm-7vm3-c6vr

больше 3 лет назад

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-17098

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

CVSS3: 9.8
31%
Средний
около 8 лет назад
github логотип
GHSA-pmxm-7vm3-c6vr

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

CVSS3: 9.8
31%
Средний
больше 3 лет назад

Уязвимостей на страницу