CVE-2007-0850
scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- syscp team/syscp
- Source
- cve@mitre.org
References
- http://osvdb.org/33127
- http://secunia.com/advisories/24102
- http://www.securityfocus.com/archive/1/459397/100/0/threaded
- http://www.securityfocus.com/bid/22454Exploit, Vendor Advisory
- http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32330
- http://osvdb.org/33127
- http://secunia.com/advisories/24102
- http://www.securityfocus.com/archive/1/459397/100/0/threaded
- http://www.securityfocus.com/bid/22454Exploit, Vendor Advisory
- http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32330
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.