install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3) database_password, or (4) database_name parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-01-23T19:00:00
Updated: 2024-08-05T05:40:51.360Z
Reserved: 2018-01-17T00:00:00
Link: CVE-2018-5749
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-23T19:29:00.247
Modified: 2024-11-21T04:09:18.733
Link: CVE-2018-5749
Redhat
No data.