ZeroHour

CVE-2018-10429

PoC
CVSS 3.0
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.

Vendors
cosmocms
Products
cosmo
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.