Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vBulletin misc.php template名远程代码注入漏洞
Vulnerability Description
vBulletin是一款开放源代码PHP论坛程序。 vBulletin对用户提交的template名输入缺少充分过滤,远程攻击者可以利用这个漏洞进行代码注入攻击,以Web进程的权限执行任意命令。 在当Add Template Name in HTML Comments功能开启的时候,用户可以提交恶意代码给template变量值,从而执行任意代码或获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A