scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Syscp | Syscp_team | 1.2.10 (including) | 1.2.10 (including) |
| Syscp | Syscp_team | 1.2.15 (including) | 1.2.15 (including) |