Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-09607
HistoryFeb 10, 2023 - 12:00 a.m.

phpwcms directory traversal vulnerability

2023-02-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
phpwcms
directory traversal
vulnerability
remote attacker
arbitrary files
php/mysql
web server platform
act_ftptakeover.php
cnvd

EPSS

0.001

Percentile

48.5%

phpwcms is an open source Web content management system. It is fast, easy to install and runs on any standard web server platform that supports PHP/MySQL. phpwcms version 1.9.25 is vulnerable to a directory traversal vulnerability. A remote attacker can exploit this vulnerability to delete arbitrary files via the unfiltered $file parameter in the include/inc_act/act_ftptakeover.php file.

EPSS

0.001

Percentile

48.5%

Related for CNVD-2023-09607