outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
References
Configurations
History
09 Jan 2024, 21:20
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Outdoorbits little Backup Box
Outdoorbits |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:outdoorbits:little_backup_box:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b59897c765d6ba9313faa - Patch | |
| References | () https://www.php.net/manual/en/function.extract - Product |
30 Dec 2023, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-12-30 19:15
Updated : 2024-01-09 21:20
NVD link : CVE-2023-52262
Mitre link : CVE-2023-52262
JSON object : View
Products Affected
outdoorbits
- little_backup_box
CWE
