Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MoniWiki远程任意命令执行漏洞
Vulnerability Description
MoniWiki是一款韩文的WIKI WEB应用程序。 MoniWiki不正确过滤用户提交的输入,远程攻击者可以利用这个漏洞以WEB进程执行任意命令。 "UploadFile.php"不正确检查上传文件扩展名,攻击者可以提交任意脚本文件(php、pl、cgi等)到WEB服务器,并通过mod_php模块以WEB进程权限执行。
CVSS Information
N/A
Vulnerability Type
N/A