phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to injected scripts, or by injecting PHP into a PHP configuration variable via a PHP variable variable.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-07-21T14:00:00
Updated: 2024-08-06T05:47:57.906Z
Reserved: 2015-05-04T00:00:00
Link: CVE-2015-3638
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-07-21T14:29:00.490
Modified: 2024-11-21T02:29:32.607
Link: CVE-2015-3638
Redhat
No data.