Security Advisory

CVE-2019-9082

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-02-24 18:00:00
Last updated 2025-12-09 14:38:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.