Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ganglia PHP RRD Web客户端远程执行任意命令漏洞
Vulnerability Description
Ganglia是一个可扩展的集群监视管理系统,它从一个分散,分布的计算机中收集和组合一系列系统性能信息。Ganglia项目还为Ganglia系统提供了一个基于PHP的客户端程序。 Ganglia PHP客户端存在输入验证漏洞,可以使攻击者在主机上以Web服务器进程权限执行任意命令。 脚本graph.php未对用户输入作充份过滤,攻击者可以在输入中插入shell命令,以主机上以Web服务器进程执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A