CVE-2018-10642
02.05.2018, 07:29
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
Vendor | Product | Version |
---|---|---|
combodo | itop | 𝑥 ≤ 2.4.1 |
𝑥
= Vulnerable software versions