CVE-2018-7735

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/03/2018
Last modified:
26/03/2018

Description

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:afian:filerun:*:*:*:*:*:*:*:* 2017.09.25 (including)