admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://antoniocannito.it/?p=137#rce2 | third party advisory exploit |
http://packetstormsecurity.com/files/156751/PHPKB-Multi-Language-9-Authenticated-Remote-Code-Execution.html | exploit vdb entry third party advisory |
https://antoniocannito.it/phpkb1#authenticated-remote-code-execution-cve-2020-10389 | third party advisory exploit |
https://www.exploit-db.com/exploits/48219 | exploit vdb entry third party advisory |