scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Syscp | Syscp_team | 1.2.10 (including) | 1.2.10 (including) |
Syscp | Syscp_team | 1.2.15 (including) | 1.2.15 (including) |