CVE-2020-10948

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
01/04/2020
Last modified:
21/07/2021

Description

Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alienform2_project:alienform2:2.0.2:*:*:*:*:*:*:*