CVE-2021-39503
07.09.2021, 20:15
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Vendor | Product | Version |
---|---|---|
phpmywind | phpmywind | 5.6 |
𝑥
= Vulnerable software versions