PHPKit 1.6.1中的admin/admin.php页面存在无限制文件上传漏洞。这使得远程认证管理员可以通过上传.php文件到content/images/目录(利用images.php)来执行任意PHP代码。注:如果PHPKit管理员必须访问终端系统以安装或修改产品的配置,此问题可能不能越过权限界限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2005-2693 | CVS Cvsbug.In Script 不安全临时文件创建漏洞 | |
| CVE-2005-2694 | WinAce 缓冲区溢出 | |
| CVE-2005-2695 | Cisco IDS传感器CiscoWorks管理中心 SSL证书验证漏洞 | |
| CVE-2005-2696 | IBM Lotus Notes 敏感信息泄露漏洞 | |
| CVE-2005-2697 | MyBulletinBoard 'search.php' SQL注入漏洞 | |
| CVE-2005-2698 | Nephp Publisher Enterprise 'browse.php' 跨站脚本攻击漏洞 |
No comments yet