'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-22 | |
| Rule Name: | Byzoro Smart S45F importexport.php Command Injection Vulnerability (CVE-2023-4873) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument sql leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-239358 is the identifier assigned to this vulnerability. | |
| Impact: | Unauthenticated remote attackers can inject OS commands via the sql parameter of /importexport.php, leveraging SQL INTO OUTFILE to write a PHP webshell and achieve full remote code execution. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://github.com/cugerQDHJ/cve/blob/main/rce.md https://vuldb.com/?ctiid.239358 |
|
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |