CVE-2019-13956
18.07.2019, 18:15
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).
Vendor | Product | Version |
---|---|---|
codersclub | discuz\!ml | 3.2 ≤ 𝑥 ≤ 3.4 |
𝑥
= Vulnerable software versions