Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mantis JpGraph库远程任意文件可包含漏洞
Vulnerability Description
Mantis是一款基于WEB的PHP编写MySQL后台支持的漏洞跟踪系统。 Mantis的summary_graph_functions.php脚本对用户的输入缺少检查,远程攻击者可以利用这个漏洞包含远程服务器上的文件以WEB进程权限执行任意命令。 Mantis使用JpGraph库来生成一些统计图,部分代码储存在一个包含文件(summary_graph_functions.php)中,这个文件调用include()函数加载JpGraph库。JpGraph库的地址是储存在一个配置文件中的,而summary_
CVSS Information
N/A
Vulnerability Type
N/A