HIGH
scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table
Published Feb 8, 2007
7.5
HIGHCVSS 2.0
EPSS 2.63%
Description
Affected products
Remediation
Metrics
References (6)
Change history (0)
No recorded changes yet.