漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in ELSEIF CMS.
漏洞信息
N/A
漏洞
N/A
漏洞
ELSEIF CMS 'upload.php' alphanumeric参数多个输入验证漏洞
漏洞信息
ELSEIF CMS Beta 0.6不能正确解除变数,当输入参数包含含有一个alphanumeric参数碎片值相匹配值的一个数据参数时,远程攻击者可以借助externe/swfupload/upload.php上载一个.php文件执行任意PHP代码。
漏洞信息
N/A
漏洞
N/A