7.5

CVE-2007-0850

Exploit
scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Syscp TeamSyscp Version1.2.10
Syscp TeamSyscp Version1.2.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.61% 0.834
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/24102
http://www.securityfocus.com/archive/1/459397/100/0/threaded
http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP
http://osvdb.org/33127
http://www.securityfocus.com/bid/22454
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/32330