668
VMScore

CVE-2017-1000423

Published: 02/01/2018 Updated: 17/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.

Vulnerable Product Search on Vulmon Subscribe to Product

b2evolution b2evolution

Exploits

b2evolution CMS versions 660 through 6810 suffer from a php code execution vulnerability ...