Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vscripts Vnews 'VNews'直接静态代码注入漏洞
Vulnerability Description
在vscripts (又称Kuba Kunkiewicz) VNews 1.2的admin/config.php中存在直接静态代码注入漏洞,远程经过身份验证的管理员可通过将代码插入到存于admin/config.php的变量中来执行代码。
CVSS Information
N/A
Vulnerability Type
N/A