Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-17370

OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.8%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2019-17370
  • Otcms » Otcms » Version: 3.85
    cpe:2.3:a:otcms:otcms:3.85


Contact Us

Shodan ® - All rights reserved