Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as demonstrated using PHP code in the _SESSION[apps][eyeOptions.eyeapp][wrapup] variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EyeOS会话远程命令执行漏洞
Vulnerability Description
eyeOS 0.8.9及之前版本中的desktop.php在调用session_start功能之前会测试_SESSION变量是否存在,从而使得远程攻击者可以通过修改关键的假定不变变量来执行任意PHP代码,并可能执行其他攻击(如演示中使用_SESSION[apps][eyeOptions.eyeapp][wrapup]变量中的PHP代码) 。
CVSS Information
N/A
Vulnerability Type
N/A