ZeroHour

CVE-2018-18485

PoC
CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directory traversal sequences in the dbname parameter. This can be leveraged to reload the product by deleting install.lock.

Vendors
phpshe
Products
phpshe
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.