← Volver a CVEs
CVE-2016-4862
N/ADescripcion
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado4/20/2017
Ultima modificacion4/20/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
cs-cart:cs-cart
Debilidades (CWE)
CWE-20
Referencias
http://jvn.jp/en/jp/JVN55389065/index.html(vultures@jpcert.or.jp)
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000157.html(vultures@jpcert.or.jp)
http://tips.cs-cart.jp/fix-twigmo-vulnerability-20160914.html(vultures@jpcert.or.jp)
http://www.securityfocus.com/bid/92992(vultures@jpcert.or.jp)
http://jvn.jp/en/jp/JVN55389065/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000157.html(af854a3a-2127-422b-91ae-364da2661108)
http://tips.cs-cart.jp/fix-twigmo-vulnerability-20160914.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/92992(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.