Aller au contenu

Fiche vulnérabilité

CVE-2024-39171 : faille critique phpvibe phpvibe (CVSS 9.8)

Description

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 juil. 2024
Dernière mise à jour
9 juil. 2026

Produits concernés

  • phpvibe phpvibe

Références

Rechercher une autre vulnérabilité dans la base CVE