A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://github.com/whiskey-jj/w2s2x2222.github.io/issues/2 | issue tracking exploit third party advisory |
https://www.cnvd.org.cn/flaw/show/2297879 | third party advisory |