Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sympoll远程文件泄露漏洞
Vulnerability Description
Sympoll是一款可定制的PHP编写的投票系统。 Sympoll对变量的完整性缺少正确的检查,远程攻击者可以利用这个漏洞以WEB服务进程的权限查看系统上任意文件内容。 Sympoll对用户提交的参数缺少充分的检查,在php.ini配置文件中'register_globals'选项为'on'的情况下,可导致远程攻击者以WEB进程的权限查看系统任意文件内容,造成敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A