CVE-2017-9741: Input Validation
Published Jun 18, 2017
·Updated
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLESPREFIX in the configuration file.
Affected Software
1 affected component
ProjectSend ProjectSend=r754
Event History
Jun 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9741?
CVE-2017-9741 has a severity rating of Medium according to the Common Vulnerability Scoring System.
2
How do I fix CVE-2017-9741?
To fix CVE-2017-9741, update ProjectSend to a version later than r754 where the vulnerability has been patched.
3
What type of vulnerability is CVE-2017-9741?
CVE-2017-9741 is a remote code execution vulnerability that affects ProjectSend.
4
What conditions must be met for CVE-2017-9741 to be exploited?
CVE-2017-9741 can be exploited by attackers who can send a crafted dbprefix parameter to the install/make-config.php script.
5
Which software is affected by CVE-2017-9741?
CVE-2017-9741 specifically affects ProjectSend version r754.