An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the admin/index.php?m=database&c=del sql parameter because del_action() in admin/model/database.class.php mishandles this parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpyun | Phpyun | 4.6 (including) | 4.6 (including) |