CVE-2020-18885

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

PHPMyWind是一个品牌,一款基于PHP+MySQL开发符合W3C标准的建站引擎 © 2010 - 2017
GitHubGitHub
59