1 results (0.001 seconds)

CVSS: 6.5EPSS: 0%CPEs: 12EXPL: 0

PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role. PC-EGG pWebManager en versiones anteriores a 3.3.10 y en versiones anteriores a 2.2.2 para PHP 4.x permite a usuarios remotos autenticados ejecutar comandos del SO arbitrarios aprovechando el rol editor. • http://jvn.jp/en/jp/JVN25323093/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2015-000180 http://www.pwebmanager.org • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •