Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via a crafted argument to the nome_evento parameter to phpwcms_code_snippets/mail_file_form.php and (2) sample_ext_php/mail_file_form.php, which is processed by the render_PHPcode function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpwcms 多个'nome_evento'参数代码执行漏洞
Vulnerability Description
phpwcms 存在代码执行漏洞。由于没有正确的过滤脚本phpwcms_code_snippets/mail_file_form.php和sample_ext_php/mail_file_form.php的 nome_evento 参数的值,远程攻击者可以借助此漏洞,执行任意的代码。
CVSS Information
N/A
Vulnerability Type
N/A