Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Cheiff

#26310de 56,326
9.8CVSS total
Vulnerabilidades · 1
PT-2017-11961
9.8
2017-08-21
Codiad · Codiad · CVE-2017-11366
**Name of the Vulnerable Software and Affected Versions** Codiad versions prior to 2.8.4 **Description** The issue allows for remote command execution because shell commands can be embedded in parameter values. This is demonstrated by the `search file type` parameter. **Recommendations** For versions prior to 2.8.4, update to version 2.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the `class.filemanager.php` file until a patch is available. Avoid using the `search file type` parameter in the affected API endpoint until the issue is resolved.