Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php. NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
b2evolution 多个PHP远程文件包含漏洞
Vulnerability Description
**有争议的** b2evolution中存在多个PHP远程文件包含漏洞。远程攻击者可以借助提交到blogs/中的(a)a_noskin.php,(b)a_stub.php,(c)admin.php,(d)contact.php,(e)default.php,(f)index.php和(g)multiblogs.php文件的(1)inc_path参数和到blogs/admin.php的(2)view_path和(3)control_path参数以及到(h)blogs/contact.php的(4)skin
CVSS Information
N/A
Vulnerability Type
N/A