Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
bj_sintay sitex 未限制文件上传漏洞
Vulnerability Description
sitex中存在未限制文件上传漏洞。远程攻击者可以借助一个包含有双扩展名的avatar文件名,比如.php,上传任意的PHP代码。它会导致校验失败和被保存为一个.php文件。
CVSS Information
N/A
Vulnerability Type
N/A