PoC Index

CVE-2018-17984

HIGH 7.8EPSS 3.4%

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

CVSS v3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.37% chance of exploitation in the next 30 days, 88th percentile
Published
2018-10-04
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related