PT-2018-18077 · Cms Made Simple · Cms Made Simple

Keerati T

·

Publicado

2018-02-26

·

Atualizado

2018-03-22

·

CVE-2018-7448

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CMS Made Simple version 2.1.6
Description A remote code execution issue exists, allowing attackers to inject arbitrary PHP code via the timezone parameter in step 4 of a fresh installation procedure, specifically in the /cmsms-2.1.6-install.php/index.php endpoint.
Recommendations For CMS Made Simple version 2.1.6, avoid using the timezone parameter in the /cmsms-2.1.6-install.php/index.php endpoint until a fix is available. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7448

Produtos afetados

Cms Made Simple