FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://reference1.example.com/index.php/admin/template_file/editFile.html | broken link |
https://gist.github.com/cyb3res3c/ceacf7d560d2c8cd5ffd158abf0bfba9 | exploit third party advisory |