Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Server-side request forgery in Wcms 0.3.2 lets an attacker send crafted requests from the back-end server of a vulnerable web application via the path parameter to wex/cssjs.php. It can help identify open ports, local network hosts and execute command on local services.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.