xdebug Unauthenticated OS Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 2 May 2018.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a vulnerability in the eval command present in Xdebug versions 2.5.5 and below. This allows the attacker to execute arbitrary php code as the context of the web user.

    Continue reading...
     

Share This Page

Loading...