In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-07-14T21:15:13

Updated: 2020-07-14T21:15:13

Reserved: 2020-03-30T00:00:00


Link: CVE-2020-11084

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-07-14T22:15:10.623

Modified: 2021-11-04T17:29:32.463


Link: CVE-2020-11084

JSON object: View

cve-icon Redhat Information

No data.