LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/SQYY/CVE/blob/master/Lvyecms_G.txt |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-11-20T19:00:00
Updated: 2024-08-05T20:35:21.316Z
Reserved: 2017-11-20T00:00:00
Link: CVE-2017-16903
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-11-20T19:29:00.327
Modified: 2024-11-21T03:17:12.743
Link: CVE-2017-16903
Redhat
No data.