Description
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
Remediation
References
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3834)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4466)
WordPress Plugin WP Js External Link Info Open Redirect (1.21)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2009-1387)
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)