Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shell metacharacters in the eping_count parameter or (2) restricted shell metacharacters such as ">" and "&" in the eping_host parameter, which is not handled by the validation function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ePing plugin 任意代码执行漏洞
Vulnerability Description
e107站点的ePing插件1.02及其早期版本中的doping.php允许远程攻击者可以借助于(1)eping_count参数中的shell元字符或(2)eping_host参数中的受限元字如">"和"&"执行任意的代码或重写文件。上述参数并没有通过验证功能验证。
CVSS Information
N/A
Vulnerability Type
N/A