PT-2019-14366 · Sitos · Sitos Six

Published

2019-10-07

·

Updated

2020-08-24

·

CVE-2019-15746

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SITOS six Build version 6.2.1
Description The issue allows an attacker to inject arbitrary PHP commands, potentially compromising the running server and enabling the execution of system commands in the context of the web user.
Recommendations For SITOS six Build version 6.2.1, update to a version that fixes the arbitrary PHP command injection issue to prevent server compromise and unauthorized command execution.

Fix

OS Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15746

Affected Products

Sitos Six