Логотип exploitDog
bind:CVE-2019-17613
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-17613

Количество 2

Количество 2

nvd логотип

CVE-2019-17613

больше 6 лет назад

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4vq4-r5xv-jfr9

больше 3 лет назад

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-17613

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.

CVSS3: 9.8
3%
Низкий
больше 6 лет назад
github логотип
GHSA-4vq4-r5xv-jfr9

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу