CVE-2017-9741

install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
References
Link Resource
https://github.com/XiaoZhis/ProjectSend/issues/1 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:projectsend:projectsend:r754:*:*:*:*:*:*:*

Information

Published : 2017-06-18 14:29

Updated : 2017-06-29 11:47


NVD link : CVE-2017-9741

Mitre link : CVE-2017-9741


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

projectsend

  • projectsend