CVE-2018-7448: OS Command Injection
Published Feb 26, 2018
·Updated
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Feb 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Jul 19, 58461
Event
03:22 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-7448?
CVE-2018-7448 is considered a critical vulnerability as it allows remote code execution.
2
How do I fix CVE-2018-7448?
To fix CVE-2018-7448, update your CMS Made Simple installation to the latest version, beyond 2.1.6.
3
What software versions are affected by CVE-2018-7448?
CVE-2018-7448 specifically affects CMS Made Simple version 2.1.6.
4
Can CVE-2018-7448 be exploited remotely?
Yes, CVE-2018-7448 can be exploited remotely, allowing attackers to execute arbitrary PHP code.
5
What parameters are involved in the exploitation of CVE-2018-7448?
The vulnerability in CVE-2018-7448 involves the 'timezone' parameter during the installation process.