Логотип exploitDog
bind:CVE-2019-6339
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-6339

Количество 5

Количество 5

ubuntu логотип

CVE-2019-6339

больше 6 лет назад

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2019-6339

больше 6 лет назад

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2019-6339

больше 6 лет назад

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8. ...

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-8cw5-rv98-5c46

больше 3 лет назад

Arbitrary PHP code execution in Drupal

CVSS3: 9.8
EPSS: Высокий
fstec логотип

BDU:2019-04785

больше 6 лет назад

Уязвимость утилиты phar CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-6339

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
77%
Высокий
больше 6 лет назад
nvd логотип
CVE-2019-6339

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
77%
Высокий
больше 6 лет назад
debian логотип
CVE-2019-6339

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8. ...

CVSS3: 9.8
77%
Высокий
больше 6 лет назад
github логотип
GHSA-8cw5-rv98-5c46

Arbitrary PHP code execution in Drupal

CVSS3: 9.8
77%
Высокий
больше 3 лет назад
fstec логотип
BDU:2019-04785

Уязвимость утилиты phar CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
77%
Высокий
больше 6 лет назад

Уязвимостей на страницу