Beveiligingsadvies

CVE-2018-20062

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-12-11 18:00:00
Laatst bijgewerkt 2025-10-21 23:45:46
Toegewezen door mitre
CVSS-score 9.8
Status PUBLISHED

Beschrijving

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.