First published: Thu Dec 10 2020(Updated: )
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-19142 is critical with a CVSS score of 9.8.
Attackers can exploit CVE-2020-19142 by executing arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
iCMS version 7.0.0 is affected by CVE-2020-19142.
At the moment, there is no known fix for CVE-2020-19142. It is recommended to update to a patched version when available.
You can find more information about CVE-2020-19142 at the following link: [https://github.com/idreamsoft/iCMS/issues/65](https://github.com/idreamsoft/iCMS/issues/65)