SSRF Vulnerability in tpshop 2.0.5 and 2.0.6: Remote Information Disclosure and Command Execution

SSRF Vulnerability in tpshop 2.0.5 and 2.0.6: Remote Information Disclosure and Command Execution

CVE-2017-16614 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.

Learn more about our Cis Benchmark Audit For Server Software.