|
|||
Rule General Information |
---|
Release Date: | 2019-02-07 | |
Rule Name: | NoneCMS Code Execution Vulnerability -1 (CVE-2018-20062) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | NoneCMS is an open source CMS for building corporate web sites, personal blogs, and mobile support. There is a security vulnerability in NoneCMS version 1.3 that remote attackers can exploit to execute arbitrary PHP code with the 'filter' parameter. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | https://github.com/nangge/noneCms/issues/21 |
|
Solutions |
---|
Refer to the announcement or patch by the vendor: https://www.tibco.com/support/advisories/2018/12/tibco-security-advisory-december-11-2018-tibco-managed-file-transfer |