ZeroHour

CVE-2018-17984

PoC ×2
CVSS 3.0
7.8 high
EPSS
3%p88
Published
()
Modified
Description

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

Vendors
ispconfig
Products
ispconfig
Weakness
CWE-185
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.