PT-2007-2293 · Syscp · Syscp
Published
2007-02-08
·
Updated
2018-10-16
·
CVE-2007-0850
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SysCP versions 1.2.15 and earlier
Description:
The issue allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to the panel cronscript table in the SysCP database. This is possible because the scripts/cronscript.php file in SysCP includes and executes arbitrary PHP scripts referenced by this table.
Recommendations:
For SysCP versions 1.2.15 and earlier, consider restricting database write privileges to prevent attackers from modifying the panel cronscript table until a fix is available. As a temporary workaround, monitor the panel cronscript table for any suspicious entries and remove them promptly to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Syscp