EXPOSURES › CVE-2024-39171
CVE-2024-39171
CRITICAL
DETAIL
SourceNVD · cve
Published2024-07-09
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-39171 ↗
⚡ RCE
◐ ZERO-DAY
SHAME 50/100
rcezero-day
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.