PT-2018-14770 · Pboot · Pbootcms
88Ai
·
Published
2018-11-07
·
Updated
2018-12-12
·
CVE-2018-19053
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PbootCMS version 1.2.2
Description
The issue allows remote attackers to execute arbitrary PHP code. This can be achieved by specifying a .php filename in a "SET GLOBAL general log file" statement, followed by a SELECT statement containing the PHP code.
Recommendations
For PbootCMS version 1.2.2, consider restricting access to the SQL interface to prevent the execution of malicious SQL statements until a patch is available. As a temporary workaround, avoid using the
general log file variable in SQL statements to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pbootcms