Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in visitor.php in Butterfly online visitors counter 1.08, when used with certain older versions of PHP with improper SERVER superglobal handling, allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Butterfly online visitors counter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Butterfly 'visitor.php'PHP远程文件包含漏洞
Vulnerability Description
Butterfly 在线访问者柜台1.08版本的visitor.php中存在PHP远程文件包含漏洞,当在某些具有不当SERVER超全球链接处理的PHP处理软件版本中运行时,远程攻击者可以借助_SERVER[DOCUMENT_ROOT]参数中的一个URL,执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A