cve/2018/CVE-2018-19462.md
2024-05-26 14:27:05 +02:00

649 B

CVE-2018-19462

Description

admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.

POC

Reference

No PoCs from references.

Github