Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Crea-Book 'configurer2.php'多个直接静态代码注入漏洞
Vulnerability Description
Crea-Book的admin/configurer2.php中存在多个直接静态代码注入漏洞。远程认证管理员可以借助"Fond de la page"(背景颜色)字段和其他未明字段,执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A