THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-39165

Assignermitre
Reserved2024-06-21
Published2024-07-04
Updated2024-07-04

Description

QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.

References

https://www.synacktiv.com/advisories/jpgraph-professional-version-pre-authenticated-remote-code-execution

cve.org CVE-2024-39165

nvd.nist.gov CVE-2024-39165

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39165