The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via complex curly syntax in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbseo | Crawlability | * | 3.6.0 (including) |
Vbseo | Crawlability | 2.0.0 (including) | 2.0.0 (including) |
Vbseo | Crawlability | 2.1.0 (including) | 2.1.0 (including) |
Vbseo | Crawlability | 2.1.1 (including) | 2.1.1 (including) |
Vbseo | Crawlability | 2.2.0 (including) | 2.2.0 (including) |
Vbseo | Crawlability | 2.3.0 (including) | 2.3.0 (including) |
Vbseo | Crawlability | 2.4.0 (including) | 2.4.0 (including) |
Vbseo | Crawlability | 2.4.5 (including) | 2.4.5 (including) |
Vbseo | Crawlability | 3.0.0 (including) | 3.0.0 (including) |
Vbseo | Crawlability | 3.0.0-rc2 (including) | 3.0.0-rc2 (including) |
Vbseo | Crawlability | 3.0.0-rc3 (including) | 3.0.0-rc3 (including) |
Vbseo | Crawlability | 3.0.0-rc4 (including) | 3.0.0-rc4 (including) |
Vbseo | Crawlability | 3.0.0-rc5 (including) | 3.0.0-rc5 (including) |
Vbseo | Crawlability | 3.0.0-rc6 (including) | 3.0.0-rc6 (including) |
Vbseo | Crawlability | 3.1.0 (including) | 3.1.0 (including) |
Vbseo | Crawlability | 3.2.0 (including) | 3.2.0 (including) |
Vbseo | Crawlability | 3.2.0-rc4 (including) | 3.2.0-rc4 (including) |
Vbseo | Crawlability | 3.2.0-rc5 (including) | 3.2.0-rc5 (including) |
Vbseo | Crawlability | 3.2.0-rc7 (including) | 3.2.0-rc7 (including) |
Vbseo | Crawlability | 3.2.0-rc8 (including) | 3.2.0-rc8 (including) |
Vbseo | Crawlability | 3.3.0 (including) | 3.3.0 (including) |
Vbseo | Crawlability | 3.3.0-rc1 (including) | 3.3.0-rc1 (including) |
Vbseo | Crawlability | 3.3.0-rc2 (including) | 3.3.0-rc2 (including) |
Vbseo | Crawlability | 3.3.1 (including) | 3.3.1 (including) |
Vbseo | Crawlability | 3.5.0 (including) | 3.5.0 (including) |
Vbseo | Crawlability | 3.5.0-beta1 (including) | 3.5.0-beta1 (including) |
Vbseo | Crawlability | 3.5.0-beta2 (including) | 3.5.0-beta2 (including) |
Vbseo | Crawlability | 3.5.0-rc1 (including) | 3.5.0-rc1 (including) |
Vbseo | Crawlability | 3.5.0-rc2 (including) | 3.5.0-rc2 (including) |
Vbseo | Crawlability | 3.5.0-rc3 (including) | 3.5.0-rc3 (including) |
Vbseo | Crawlability | 3.5.1 (including) | 3.5.1 (including) |
Vbseo | Crawlability | 3.5.2 (including) | 3.5.2 (including) |
Vbseo | Crawlability | 3.6.0-beta1 (including) | 3.6.0-beta1 (including) |
Vbseo | Crawlability | 3.6.0-rc1 (including) | 3.6.0-rc1 (including) |
Vbseo | Crawlability | 3.6.0-rc2 (including) | 3.6.0-rc2 (including) |