Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Easy CMS choose_file.php 任意文件上传漏洞
Vulnerability Description
Easy CMS是基于PHP的开放源码内容管理系统。 Easy CMS的choose_file.php文件没有正确过滤非法的文件扩展名,允许攻击者上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A