Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vBulletin Calendar远程执行任意命令漏洞
Vulnerability Description
vBulletin Calendar是一款基于WEB的日历程序。 vBulletin Calendar对用户输入缺少正确过滤,远程攻击者可以利用这个漏洞以WEB权限在系统上执行任意命令。 vBulletin Calendar中的calendar.php脚本对用户提交给comma参数的值缺少过滤,攻击者提交特殊字符并追加任意系统命令,可能以WEB进程的权限(一般是nobody)在系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A