CVE-2014-9185 Information
Feb 14, 2021
cve
Description
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
Reference
http://packetstormsecurity.com/files/129624/Morfy-CMS-1.05-Remote-Command-Execution.html http://seclists.org/fulldisclosure/2014/Dec/70 http://www.securityfocus.com/archive/1/534271/100/0/threaded http://www.vulnerability-lab.com/get_content.php?id=1367 https://github.com/Awilum/monstra-cms/issues/351 Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
Share on: