CVE-2017-9771
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_password parameter.
CRITICAL · CVSS 9.8
EPSS 0.00783
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0