Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
epesi framework 远程任意文件执行漏洞
Vulnerability Description
epesi framework 0.8.6版本之前的版本没有适当校验文件扩展名,这会允许远程攻击者可以借助涉及画廊图像上传特性的未明向量, 上传并执行任意PHP指令。
CVSS Information
N/A
Vulnerability Type
N/A