Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4675
HistoryJul 25, 2017 - 10:42 p.m.

Remote Code Execution (RCE) Through Deserialization

2017-07-2522:42:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.003

Percentile

70.3%

Subrion CMS is vulnerable to remote code execution (RCE). A malicious user can and execute arbitrary code by passing a string of a serialized object to the server through $_COOKIE['salt'] when submitting a login request. This causes the server to execute the unserialize() function that will result in arbitrary code being executed on the server.

EPSS

0.003

Percentile

70.3%

Related for VERACODE:4675