vendor:
jPORTAL
by:
irk4z
7.5
CVSS
HIGH
Remote PHP Code Execution
CWE
Product Name: jPORTAL
Affected Version From: 2.3.2001
Affected Version To: 2.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
jPORTAL 2.3.1 & UserPatch (forum.php) Remote PHP Code Execution Exploit
This exploit allows remote attackers to execute arbitrary PHP code on the target system.
Mitigation:
Update to a patched version of jPORTAL and UserPatch.