components/filemanager/class.filemanager.php in Codiad before 2.8.3 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type
.
CPE | Name | Operator | Version |
---|---|---|---|
codiad/codiad | eq | 1.3.6 |
www.jianshu.com/p/41ac7ac2a7af
github.com/Codiad/Codiad
github.com/Codiad/Codiad/commit/ca5089eeba42d16ce3a7f86be628ac7750780111
github.com/Codiad/Codiad/issues/1011
github.com/Codiad/Codiad/pull/1013
github.com/Codiad/Codiad/pull/1013/commits/b3645b4c6718cef6de7003f41aafe7bfcc0395d1
nvd.nist.gov/vuln/detail/CVE-2017-11366