LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/SQYY/CVE/blob/master/Lvyecms_G.txt |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2017-11-20T19:00:00
Updated: 2024-08-05T20:35:21.316Z
Reserved: 2017-11-20T00:00:00
Link: CVE-2017-16903

No data.

Status : Deferred
Published: 2017-11-20T19:29:00.327
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-16903

No data.