← Back to CVE List

CVE-2017-16614

Published: 2018-03-30T21:29Z
Last Modified: 2024-11-21T03:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt