htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/530891/100/0/threaded | mailing list exploit vdb entry third party advisory |
https://www.htbridge.com/advisory/HTB23198 | third party advisory exploit |
https://bugs.launchpad.net/eventum/+bug/1271499 | issue tracking exploit third party advisory |
http://bazaar.launchpad.net/~eventum-developers/eventum/trunk/revision/4665 | third party advisory patch |