PT-2019-15110 · Otcms · Otcms
Published
2019-10-09
·
Updated
2021-07-21
·
CVE-2019-17370
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OTCMS version 3.85
Description
The issue allows for arbitrary PHP code execution. This is due to insufficient blocking of certain SQL manipulations in the
admin/sysCheckFile deal.php file, specifically not blocking the "into/**/outfile" manipulation in a SELECT statement. This enables an attacker to create a .php file.Recommendations
For OTCMS version 3.85, consider restricting access to the
admin/sysCheckFile deal.php file until a proper fix is applied, and ensure that any SQL queries are properly sanitized to prevent such manipulations.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otcms