Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Advanced GuestBook addentry.php 远程文件包含漏洞
Vulnerability Description
Advanced GuestBook是一款流行的PHP论坛程序phpBB的组件。 Advanced GuestBook实现上存在输入验证漏洞,远程攻击者可能利用此漏洞在服务器上以Web进程权限执行任意命令。 Advanced GuestBook的addentry.php脚本没有对phpbb_root_path变量值的内容做充分的过滤就在脚本中引用,导致攻击者可以使之包含远程机器上的PHP脚本进行执行。
CVSS Information
N/A
Vulnerability Type
N/A