Vulnerabilities > Syscp Project

DATE CVE VULNERABILITY TITLE RISK
2019-11-07 CVE-2010-2476 Improper Input Validation vulnerability in Syscp Project Syscp 1.4.2.1
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.
network
low complexity
syscp-project CWE-20
critical
9.8