Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier allows remote attackers to upload PHP code to the images/contact folder via a filename with a double extension in the contact_attach parameter in a contact option in index.php, which bypasses an insufficiently restrictive regular expression.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Limbo CMS 'contact.html.php' 不受限制的文件上传漏洞
Vulnerability Description
Limbo(也称为Lite Mambo)CMS 1.0.4.2L及更早版本的Contact (com_contact)组件中的contact.html.php内的不受限制的文件上传漏洞,远程攻击者可以通过在index.php的contact选项的contact_attach参数中具有双扩展名的文件名,绕过未进行充分限制的正则表达式,以此将PHP代码上传到images/contact文件夹中。
CVSS Information
N/A
Vulnerability Type
N/A