CVE-2017-9741
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix param
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
CRITICAL · CVSS 9.8
EPSS 0.00799
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0