SSRF Vulnerability in tpshop 2.0.5 and 2.0.6: Remote Information Disclosure and Command Execution
CVE-2017-16614 · HIGH Severity
AV:N/AC:L/AU:N/C:P/I:P/A:P
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.
Learn more about our Cis Benchmark Audit For Server Software.