CVE-2022-35914
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
- Glpi-project Glpi
- ≤ 10.0.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.7% (100th percentile)
- Weakness
- CWE-74
- NVD status
- Analyzed
- Published
- 2022-09-19
CVE-2022-35914 at NVD
15 known exploits for CVE-2022-35914
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Injection in Glpi-Project Glpi
Exploit for Injection in Glpi-Project Glpi
Exploit for Injection in Glpi-Project Glpi
Exploit for SQL Injection in Dolibarr
Exploit for Injection in Glpi-Project Glpi
htmlLawed 1.2.5 - Remote Code Execution Exploit
htmlLawed 1.2.5 - Remote Code Execution (RCE)
htmlLawed 1.2.5 Remote Command Execution
Exploit for Injection in Glpi-Project Glpi
Exploit for Injection in Glpi-Project Glpi
GLPI 10.0.2 Command Injection Exploit
GLPI 10.0.2 Command Injection
Exploit for Injection in Glpi-Project Glpi
Exploit for Injection in Glpi-Project Glpi
GLPI htmLawed php command injection