Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Nuke NukeAI直接静态代码注入漏洞
Vulnerability Description
PHP-Nuke的NukeAI 0.0.3 Beta模块中存在直接静态代码注入漏洞。远程攻击者可借助文件名加载并执行任意PHP代码,该文件名带有filename参数中的.php扩展和moreinfo参数中的代码。
CVSS Information
N/A
Vulnerability Type
N/A