CVE-2018-8756: Code Injection
Published Mar 18, 2018
·Updated
Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=membercontent&a=init request.
Affected Software
1 affected component
YzmCMS YzmCMS=3.7.1
Event History
Mar 18, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8756?
CVE-2018-8756 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-8756?
To fix CVE-2018-8756, upgrade YzmCMS to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2018-8756 enable?
CVE-2018-8756 enables remote attackers to execute arbitrary code through eval injection.
4
Which version of YzmCMS is affected by CVE-2018-8756?
CVE-2018-8756 affects YzmCMS version 3.7.1.
5
Can CVE-2018-8756 be exploited through user input?
Yes, CVE-2018-8756 can be exploited via PHP code in the POST data of specific requests.