← voltar
CVE-2016-9483

PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to unsafe deserialization of untrusted data

EPSS 3.5%CWE-502
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 3.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 jul 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.
Produtos afetados
PHP FormMail · Generator

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →