Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FlatNuke 2.5.3 直接代码注入漏洞
Vulnerability Description
FlatNuke 2.5.3中存在直接代码注入漏洞,远程攻击者将代码置入HTTP响应的Referer头文件中,导致代码被注入referer.php文件,然后通过访问此文件来执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A