CVE-2018-10085 (cms_made_simple)

CVE-2018-10085 (cms_made_simple)

CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of libclassesinternalclass.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.

Source: CVE-2018-10085 (cms_made_simple)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다