ZeroHour

CVE-2018-18083

PoC ×2
CVSS 3.0
9.8 critical
EPSS
2%p84
Published
()
Modified
Description

An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.

Vendors
comsenz
Products
duomicms
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.