CVE-2018-19053: Code Injection
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL generallogfile" statement, followed by a SELECT statement containing this PHP code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19053?
CVE-2018-19053 is a vulnerability in PbootCMS 1.2.2 that allows remote attackers to execute arbitrary PHP code.
How can remote attackers exploit CVE-2018-19053?
Remote attackers can exploit CVE-2018-19053 by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing the PHP code they want to execute.
What is the severity of CVE-2018-19053?
The severity of CVE-2018-19053 is high, with a severity value of 7.2.
How do I fix CVE-2018-19053?
To fix CVE-2018-19053, it is recommended to update PbootCMS to a version that has addressed the vulnerability.
Where can I find more information about CVE-2018-19053?
More information about CVE-2018-19053 can be found at the following reference: https://github.com/Pbootcms/Pbootcms/issues/2