CVE-2018-19462
07.06.2019, 17:29
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
Vendor | Product | Version |
---|---|---|
phome | empirecms | 𝑥 ≤ 7.5.0 |
𝑥
= Vulnerable software versions
References