7.5
CVSSv2

CVE-2019-13956

Published: 18/07/2019 Updated: 31/07/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Discuz!ML 3.2 up to and including 3.4 allows remote malicious users to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codersclub discuz\\!ml

Github Repositories

Discuz!ML RCE

Discuz ML RCE CVE ID : CVE-2019-13956 URL: wwwesolnnet/blog/2019/06/14/discuzml-v-3-x-code-injection-vulnerability/ CVE URL: nvdnistgov/vuln/detail/CVE-2019-13956 CVE Mitre : cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-13956 Discuz!ML 32 through 34 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as de

CVE-2019-13956 cd CVE-2019-13956 docker-compose up -d 127001:8090