Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Windows的PHP COM执行任意代码漏洞
Vulnerability Description
Windows系统上的PHP COM扩展名允许见机行事的攻击者借助一个WScript.Shell COM对象,执行任意代码。通过使用该对象的Run方式运行cmd.exe,可以绕过PH的安全模式。
CVSS Information
N/A
Vulnerability Type
N/A