QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Dec 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
cvssV3_1
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-04T00:00:00
Updated: 2024-12-04T15:17:28.835173
Reserved: 2024-06-21T00:00:00
Link: CVE-2024-39165
Vulnrichment
Updated: 2024-07-23T15:37:51.953Z
NVD
Status : Awaiting Analysis
Published: 2024-07-04T13:15:10.023
Modified: 2024-12-04T16:15:25.093
Link: CVE-2024-39165
Redhat
No data.