install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-10T16:00:00Z
Updated: 2024-09-16T17:32:36.057Z
Reserved: 2019-02-10T00:00:00Z
Link: CVE-2019-7692
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-02-10T16:29:00.200
Modified: 2024-11-21T04:48:32.153
Link: CVE-2019-7692
Redhat
No data.