CVE-2023-28854

CVSS V2 None CVSS V3 None
Description
nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A patch was made available at commit e5409aa2d441789cbb35f6b119bef97ecc3986aa on 2023-03-30. Users should update index.php to 2023-03-30 or later or, as a workaround, add a function such as `env_patchsample230330.php` to env.php.
Overview
  • CVE ID
  • CVE-2023-28854
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-03T18:15:07
  • Last Modified Date
  • 2023-04-12T18:55:16
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nophp_project:nophp:*:*:*:*:*:*:*:* 1 OR 0.0.1
History
Created Old Value New Value Data Type Notes
2023-04-17 04:03:10 Added to TrackCVE
2023-04-17 04:03:13 Weakness Enumeration new