CVE-2026-73699
- EPSS 0.54%
- Veröffentlicht 10.09.2026 16:36:24
- Zuletzt bearbeitet 10.09.2026 19:58:20
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is u...
CVE-2026-73698
- EPSS 0.44%
- Veröffentlicht 10.09.2026 16:34:50
- Zuletzt bearbeitet 15.09.2026 15:17:21
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpola...
CVE-2026-73694
- EPSS 1.81%
- Veröffentlicht 10.09.2026 16:33:00
- Zuletzt bearbeitet 11.09.2026 19:17:45
FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Att...
CVE-2026-73693
- EPSS 1.8%
- Veröffentlicht 10.09.2026 16:31:32
- Zuletzt bearbeitet 10.09.2026 19:58:20
FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. At...
CVE-2026-14863
- EPSS 1.65%
- Veröffentlicht 11.08.2026 20:41:35
- Zuletzt bearbeitet 16.09.2026 13:42:42
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution seque...
CVE-2022-47532
- EPSS 0.63%
- Veröffentlicht 22.12.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 07:32:09
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users§ion=cpanel&page=list request.
CVE-2017-14738
- EPSS 2.62%
- Veröffentlicht 30.09.2017 01:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
CVE-2007-2469
- EPSS 1.82%
- Veröffentlicht 02.05.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:40
SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.
CVE-2007-2470
- EPSS 1.65%
- Veröffentlicht 02.05.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:40
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.