MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Link | Tags |
---|---|
https://github.com/eddietcc/CVEnotes/blob/master/MyWebSQL/RCE/readme.md | third party advisory exploit |