CVE-2018-17984
04.10.2018, 23:29
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.Enginsight
Vendor | Product | Version |
---|---|---|
ispconfig | ispconfig | 𝑥 < 3.1.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References