Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-7234

An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can then be downloaded via an admincp.php?app=apps&do=pack request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2019-7234
  • Idreamsoft » Icms » Version: 7.0.13
    cpe:2.3:a:idreamsoft:icms:7.0.13


Contact Us

Shodan ® - All rights reserved