LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8073 | LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/SQYY/CVE/blob/master/Lvyecms_G.txt |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:35:21.316Z
Reserved: 2017-11-20T00:00:00
Link: CVE-2017-16903
No data.
Status : Deferred
Published: 2017-11-20T19:29:00.327
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-16903
No data.
OpenCVE Enrichment
No data.
EUVD