First published: Tue Jan 29 2019(Updated: )
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7160 is a vulnerability in idreamsoft iCMS 7.0.13 that allows directory traversal and execution of arbitrary PHP code.
CVE-2019-7160 has a severity rating of 9.8 (Critical).
CVE-2019-7160 affects idreamsoft iCMS version 7.0.13.
CVE-2019-7160 is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
A fix is not available at the moment. It is recommended to update to a version of idreamsoft iCMS that is not affected by this vulnerability when it becomes available.