CVE-2017-16903
Last modified
CVE-2017-16903 is a vulnerability of currently unknown severity. LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.. EPSS estimates a 2.05% chance of exploitation in the next 30 days.
Description
LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lvyecms Project | Lvyecms | <= 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16903?
How severe is CVE-2017-16903?
How do I fix CVE-2017-16903?
Are you affected by CVE-2017-16903?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
