Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpBB News Defilante Horizontale模块'functions_newshr.php'远程文件包含漏洞
Vulnerability Description
News Defilante Horizontale是phpBB中所使用的一个模块。 News Defilante Horizontale模块在处理用户请求时存在输入验证漏洞,远程攻击者可能通过利用此漏洞在服务器上以Web进程权限执行任意指令。 phpBB的includes/functions_newshr.php文件没有正确的验证对phpbb_root_path参数的输入,攻击者可以通过包含本地或外部资源的文件导致执行任意PHP代码。成功攻击要求打开了register_globals。
CVSS Information
N/A
Vulnerability Type
N/A