PT-2017-11791 · Finecms · Finecms

Published

2017-07-12

·

Updated

2017-07-14

·

CVE-2017-11167

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FineCMS version 2.1.0
Description The issue allows remote attackers to execute arbitrary PHP code. This can be achieved by using a URL Manager "Add Site" action and entering the code after a ' sequence in a domain name. For example, using the phpinfo() input value demonstrates this capability.
Recommendations For FineCMS version 2.1.0, update to a version that fixes this issue to prevent remote attackers from executing arbitrary PHP code. As a temporary workaround, consider restricting access to the URL Manager "Add Site" action to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11167

Affected Products

Finecms