Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Phorum 5 'pm.php'目录遍历漏洞
Vulnerability Description
Phorum 5中的pm.php存在目录遍历漏洞。远程认证用户可以借助GLOBALS[template]参数中的目录遍历序列,包含并执行任意本地文件。比如将PHP序列注入日志文件,然后由pm.php包含。
CVSS Information
N/A
Vulnerability Type
N/A