RULE(RULE ID:321628)

Rule General Information
Release Date: 2019-02-07
Rule Name: NoneCMS Code Execution Vulnerability -2 (CVE-2018-20062)
Severity:
CVE ID:
Rule Protection Details
Description: NoneCMS is an open source CMS for building corporate web sites, personal blogs, and mobile support. There is a security vulnerability in NoneCMS version 1.4 that remote attackers can exploit to execute arbitrary PHP code with the 'filter' parameter.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: https://github.com/nangge/noneCms/issues/21
Solutions
Refer to the announcement or patch by the vendor: https://www.tibco.com/support/advisories/2018/12/tibco-security-advisory-december-11-2018-tibco-managed-file-transfer