Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dayfox Blog(dfblog) postpost.php 直接静态代码注入漏洞
Vulnerability Description
Dayfox Blog(dfblog)4版本的postpost.php中存在直接静态代码注入漏洞。当可以借助对posts.php的请求运行cat参数时,远程攻击者可以借助它,执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A