CVE-2016-7790

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.
References
Link Resource
http://www.securityfocus.com/bid/93119 Third Party Advisory VDB Entry
http://www.openwall.com/lists/oss-security/2016/09/22/6 Exploit Mailing List Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:exponentcms:exponent_cms:2.3.9:*:*:*:*:*:*:*

Information

Published : 2017-01-12 14:59

Updated : 2017-01-13 08:06


NVD link : CVE-2016-7790

Mitre link : CVE-2016-7790


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

exponentcms

  • exponent_cms