Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Prometheus应用程序架构远程文件包含漏洞
Vulnerability Description
Prometheus是一款基于WEB的应用程序架构系统,由PHP编写。 Prometheus中的prometheus-library/all.lib代码中对用户提交的要装载的库路径缺少正确检查,远程攻击者可以利用这个漏洞装载包含其他服务器上的文件,导致文件中的PHP代码以WEB用户权限执行。 prometheus-library/all.lib中包含如下问题代码: if ( ! isset( $PROMETHEUS_LIBRARY_BASE ) || $PROMETHEUS_LIBRARY_BASE ==
CVSS Information
N/A
Vulnerability Type
N/A