Vulnerabilities
Vulnerable Software
Hisiphp:  Security Vulnerabilities
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.
CVSS Score
7.2
EPSS Score
0.008
Published
2022-04-04
Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-06-21
hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-24
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).
CVSS Score
8.8
EPSS Score
0.002
Published
2018-10-01
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.
CVSS Score
7.2
EPSS Score
0.009
Published
2018-10-01


Contact Us

Shodan ® - All rights reserved