漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php; or a URL in the language_home parameter to (3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, or (7) links/submit_links.php in modules/; related to missing checks in (a) modules/moduleSec.php and (b) include/includeSec.php for inclusion of certain URLs, as demonstrated by an ftps:// URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IziContents IziContents IziContents 代码注入漏洞
Vulnerability Description
iziContents 1 RC6版本及其早期版本中存在多个不完全黑名单漏洞, 远程攻击者可以借助(1)modules/poll/poll_summary.php的admin_home参数或(2)include/db.php的rootdp参数的一个URL;或(3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, 或(7) modules/下links/submit_lin
CVSS Information
N/A
Vulnerability Type
N/A