CVE-2017-9771: Code Injection
Published Jun 21, 2017
·Updated
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the databaseusername, databasehost, or databasepassword parameter.
Affected Software
1 affected component
WebsiteBaker WebsiteBaker=2.10.0
Remediation
Patch Available
Event History
Jun 21, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9771?
CVE-2017-9771 has been classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2017-9771?
To mitigate CVE-2017-9771, upgrade WebsiteBaker to a version later than 2.10.0 where the vulnerability has been addressed.
3
What are the attack vectors for CVE-2017-9771?
CVE-2017-9771 can be exploited by attackers sending crafted input through the database_username, database_host, or database_password parameters.
4
Can CVE-2017-9771 affect my website's security?
Yes, CVE-2017-9771 can significantly compromise your website by allowing attackers to execute arbitrary PHP code remotely.
5
What versions of WebsiteBaker are affected by CVE-2017-9771?
CVE-2017-9771 specifically affects WebsiteBaker version 2.10.0.