ProjectSend (formerly cFTP) r582... CVE-2016-10731

7.5 AV AC AU C I A
发布: 2018-10-29
修订: 2018-12-18

ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息