CVE-2018-17984

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ispconfig:ispconfig:*:*:*:*:*:*:*:*

Information

Published : 2018-10-04 16:29

Updated : 2018-12-13 09:11


NVD link : CVE-2018-17984

Mitre link : CVE-2018-17984


JSON object : View

CWE
CWE-185

Incorrect Regular Expression

Advertisement

dedicated server usa

Products Affected

ispconfig

  • ispconfig