Vulnerabilities > Syscp Team > Syscp > 1.2.10
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-02-08 | CVE-2007-0850 | Local File Include vulnerability in SYSCP System Control Panel Panel_CronScript Table scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table. | 7.5 |
2005-08-16 | CVE-2005-2568 | Remote Security vulnerability in Syscp Team Syscp 1.2.10 Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval function. | 7.5 |