CVE-2018-8972

CVE-2018-8972

Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters.

Source: CVE-2018-8972

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다