Vulnerabilities
Vulnerable Software
Hisiphp:  >> Hisiphp  >> 1.0.8  Security Vulnerabilities
hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-24
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).
CVSS Score
8.8
EPSS Score
0.002
Published
2018-10-01
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.
CVSS Score
7.2
EPSS Score
0.009
Published
2018-10-01


Contact Us

Shodan ® - All rights reserved