phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
References
Link | Resource |
---|---|
https://github.com/howchen/howchen/issues/3 | Exploit Third Party Advisory |
https://github.com/howchen/howchen/issues/3 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 03:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/howchen/howchen/issues/3 - Exploit, Third Party Advisory |
Information
Published : 2018-08-31 16:29
Updated : 2024-11-21 03:52
NVD link : CVE-2018-16278
Mitre link : CVE-2018-16278
CVE.ORG link : CVE-2018-16278
JSON object : View
Products Affected
phpkaiyuancms
- phpopensourcecms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')