vendor:
FlexPaper PHP Publish Service
by:
Red Timmy Security
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: FlexPaper PHP Publish Service
Affected Version From: <= 2.3.6
Affected Version To: 2.3.2006
Patch Exists: NO
Related CWE: CVE-2018-11686
CPE: a:flexpaper:flexpaper_php_publish_service:2.3.6
Platforms Tested: Linux/Unix
2019
FlexPaper PHP Publish Service <= 2.3.6 RCE
This exploit allows remote attackers to execute arbitrary code on the target system by deleting the target configuration file and sending a crafted payload.
Mitigation:
Update to a version higher than 2.3.6.