Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 110 bronnen 3 kritiek 24 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2017-9741

CRITICAL · 9.8 CVSS Gepubliceerd: CWE-20

Beschrijving

install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.

Vendors

Projectsend

Affected products

Projectsend

References