Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
McNews install.php远程任意文件包含漏洞
Vulnerability Description
mcNews是一套允许用户在WEB上张贴新闻的脚本系统,可运行在Linux和Unix操作系统上,也可运行在Microsoft Windows操作系统下。 mcNews中存在远程文件包含漏洞,漏洞的起因是应用程序无法正确的过滤用户对install.php脚本所提供的输入,这样攻击者就可以在输入中包含任意文件,导致跨站脚本等攻击。
CVSS Information
N/A
Vulnerability Type
N/A