Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Snoopy任意命令执行漏洞
Vulnerability Description
Snoopy是一个模拟Web浏览器的PHP类,它可自动完成检索网页内容和张贴表单等任务。 Snoopy对URL的处理存在漏洞,远程攻击者可能利用此漏洞在主机上执行任意命令。 在使用Snoopy API调用请求SSL保护的网页时,会调用_httpsrequest函数,而该函数会将URL用作参数。然后该函数会未经检查用户输入便调用PHP函数exec。如果使用了特制URL的话,攻击者就可以提供任意命令,并在Web Server上执行这些命令。
CVSS Information
N/A
Vulnerability Type
N/A