PT-2011-3180 · E107 · E107 Cms

Publicado

2011-11-04

·

Atualizado

2017-08-17

·

CVE-2011-1513

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions e107 CMS versions 0.7.24 and earlier
Description The issue concerns a static code injection vulnerability. This vulnerability allows remote attackers to inject arbitrary PHP code into e107 config.php via a crafted MySQL server name when the installation script is not removed.
Recommendations For versions 0.7.24 and earlier, remove the installation script to prevent exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1513

Produtos afetados

E107 Cms