arbahayoub/POC

arbahayoub/POC

Releases0
This repository contains the proof of concept of some vulnerabilities

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().