Description
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-9723 | An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:01:14.833Z
Reserved: 2018-10-04T00:00:00.000Z
Link: CVE-2018-17984
No data.
Status : Modified
Published: 2018-10-04T23:29:00.570
Modified: 2024-11-21T03:55:19.780
Link: CVE-2018-17984
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD