You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Online IDE allows insecure code execution for php language which allows any attacker to gain system information such as - users information, files present in the directory and much more.
Allowed to use vulnerable functions and code execution in online ide for php programming language. As an attacker, users and systems information were given out by the use of code execution!!
Summary:
Online IDE allows insecure code execution for php language which allows any attacker to gain system information such as - users information, files present in the directory and much more.
Affected Domain:
https://onecompiler.com/php/42zact3d8
Severity:
High
Steps to reproduce:
Impact:
Allowed to use vulnerable functions and code execution in online ide for php programming language. As an attacker, users and systems information were given out by the use of code execution!!
PoC:
Fix:
Block the usage of such code exceptions code - sanitize user inputs
The text was updated successfully, but these errors were encountered: