Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php; or a URL in the language_home parameter to (3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, or (7) links/submit_links.php in modules/; related to missing checks in (a) modules/moduleSec.php and (b) include/includeSec.php for inclusion of certain URLs, as demonstrated by an ftps:// URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IziContents IziContents IziContents 代码注入漏洞
Vulnerability Description
iziContents 1 RC6版本及其早期版本中存在多个不完全黑名单漏洞, 远程攻击者可以借助(1)modules/poll/poll_summary.php的admin_home参数或(2)include/db.php的rootdp参数的一个URL;或(3) search/search.php, (4) poll/inlinepoll.php, (5) poll/showpoll.php, (6) links/showlinks.php, 或(7) modules/下links/submit_lin
CVSS Information
N/A
Vulnerability Type
N/A