Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://github.com/gaozhifeng/PHPMyWind/issues/4 | third party advisory issue tracking exploit |
https://cwe.mitre.org/data/definitions/77.html | technical description |