
We found results for “”
CVE-2017-10844
Good to know:

Date: August 28, 2017
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Control of Generation of Code ('Code Injection')
CWE-94Top Fix

Upgrade Version
Upgrade to version baserproject/basercms - 3.0.7;baserproject/basercms - 3.0.10;baserproject/basercms - 3.0.15;baserproject/basercms - dev-dev-3;baserproject/basercms - 3.0.9;baserproject/basercms - 3.0.12;baserproject/basercms - 3.0.14;baserproject/basercms - no_fix;baserproject/basercms - 3.0.11;baserproject/basercms - 4.0.8;baserproject/basercms - 3.0.13;baserproject/basercms - 3.0.1;baserproject/basercms - 3.0.4;baserproject/basercms - 3.0.5;baserproject/basercms - 3.0.6;baserproject/basercms - 3.0.3;baserproject/basercms - 3.0.2;baserproject/basercms - dev-dev-4
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |