Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Annuaire Netref漏洞
Vulnerability Description
Annuaire Netref 4.2中的cat_for_gen.php使得远程攻击者可以通过设置ad_direct参数来引用cat_for_gen.php,然后将该代码包含在m_for_racine参数中,之后代码再被写入cat_for_gen.php,从而执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A