Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PopSoft Digital PopPhoto Studio popp.config.loader.inc.php PHP远程文件包含漏洞
Vulnerability Description
PopSoft Digital PopPhoto Studio 3.5.4及之前版本的resources/includes/popp.config.loader.inc.php中存在PHP远程文件包含漏洞。远程攻击者可以借助 include_path参数(cfg['popphoto_base_path'] 变量)中的URL,执行任意PHP代码。 注意: Pixaria已通知CVE"PopPhoto并非Pixaria的产品。 它是PopSoft Digital的产品,只不过由Pixaria提供免费的主机服务
CVSS Information
N/A
Vulnerability Type
N/A