CVE-2023-52262

outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
Configurations

Configuration 1 (hide)

cpe:2.3:a:outdoorbits:little_backup_box:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:39

Type Values Removed Values Added
References () https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b59897c765d6ba9313faa - Patch () https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b59897c765d6ba9313faa - Patch
References () https://www.php.net/manual/en/function.extract - Product () https://www.php.net/manual/en/function.extract - Product

09 Jan 2024, 21:20

Type Values Removed Values Added
References () https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b59897c765d6ba9313faa - () https://github.com/outdoorbits/little-backup-box/commit/f39f91cd05544b3eb18b59897c765d6ba9313faa - Patch
References () https://www.php.net/manual/en/function.extract - () https://www.php.net/manual/en/function.extract - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) outdoorbits little-backup-box (taka Little Backup Box) anterior a f39f91c permite a atacantes remotos ejecutar código arbitrario porque la función de extracción de PHP se utiliza para entradas que no son de confianza.
CPE cpe:2.3:a:outdoorbits:little_backup_box:*:*:*:*:*:*:*:*
First Time Outdoorbits
Outdoorbits little Backup Box
CWE NVD-CWE-noinfo

30 Dec 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-30 19:15

Updated : 2024-11-21 08:39


NVD link : CVE-2023-52262

Mitre link : CVE-2023-52262

CVE.ORG link : CVE-2023-52262


JSON object : View

Products Affected

outdoorbits

  • little_backup_box