Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Fusion 多个本地文件包含漏洞
Vulnerability Description
PHP-Fusion 6.00.306及之前版本在Apache HTTP Server 1.3.27 和PHP 4.3.3下运行时,可以使远程认证用户使用一个包含两个或更多扩展名,以诸如 .gif等假装验证的扩展名结尾的文件名,上传任意类型的文件,比如上传然后再执行以".php.gif" 结尾并包含EXIF元数据中的PHP代码的头像文件。
CVSS Information
N/A
Vulnerability Type
N/A