Remote Code Execution Vulnerability in PbootCMS by Pbootcms
CVE-2018-19053
7.2HIGH
What is CVE-2018-19053?
PbootCMS version 1.2.2 contains a vulnerability that allows remote attackers to execute arbitrary PHP code. This can be exploited by manipulating the 'SET GLOBAL general_log_file' statement to specify a malicious .php filename, followed by a SELECT statement containing the attacker's PHP code. This vulnerability poses a significant risk, enabling attackers to potentially take control of the affected system.
