In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-07-14T21:15:13

Updated: 2024-08-04T11:21:14.654Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-14T22:15:10.623

Modified: 2021-11-04T17:29:32.463

Link: CVE-2020-11084

cve-icon Redhat

No data.