QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-04T00:00:00
Updated: 2024-08-02T04:19:20.531Z
Reserved: 2024-06-21T00:00:00
Link: CVE-2024-39165
Vulnrichment
Updated: 2024-07-23T15:37:51.953Z
NVD
Status : Awaiting Analysis
Published: 2024-07-04T13:15:10.023
Modified: 2024-11-21T09:27:16.160
Link: CVE-2024-39165
Redhat
No data.