Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Marcus Xenakis directory.php任意命令可执行漏洞
Vulnerability Description
Marcus S. Xenakis开发了一些基于WEB接口的SHELL命令,其中的directory.php是一个简单的运行在Unix服务器上的类似"ls"命令的脚本。 directory.php对用户输入过滤不充分问题,可以使攻击者从远程以httpd进程的权限在主机上执行任意命令。 directory.php使用简单的使用如下调用SHELL命令: exec("ls -la $dir",$lines,$rc); 由于没有过滤一些危险的元字符如";",可导致其他任意SHELL命令以httpd的权限来执行,通
CVSS Information
N/A
Vulnerability Type
N/A