Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a post to admin/settings.php that injects PHP code into settings.inc, which can then be executed via a direct request to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyCMS 多个输入验证漏洞
Vulnerability Description
MyCMS 0.9.8版本及其早期版本允许远程攻击者可以借助管理cookie参数,获得特权,例如向admin/settings.php进行粘贴并向PHP代码注入settings.inc。这可以借助对index.php的一个直接请求来实现。
CVSS Information
N/A
Vulnerability Type
N/A