Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE: similar code injection might be possible in a user profile.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Flat PHP Board index.php 代码注入漏洞
Vulnerability Description
Flat PHP Board中的index.php存在命令静态代码注入漏洞,当注册一个用户帐号并且该帐号可以访问用户的php文件,远程攻击者可以借助(1)用户名,(2)密码,和(3) email参数注入任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A