
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2020-13619) affects the php/exec/escapeshellarg function in Locutus PHP through version 2.0.11. This security flaw allows attackers to achieve code execution (CVE, Locutus PHP).
The vulnerability exists in the escapeshellarg function implementation within the PHP exec category of the Locutus library, which is a JavaScript implementation of PHP standard library functions. The issue affects all versions up to and including 2.0.11 (NPM Package).
The vulnerability allows attackers to execute arbitrary code on affected systems, representing a critical security risk for applications using the affected function (CVE).
The vulnerability is exploitable by attackers who can provide input to the escapeshellarg function, potentially leading to code execution (CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."