Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AuraCMS 'stat.php' 远程脚本代注入漏洞
Vulnerability Description
AuraCMS 1.62的stat.php以及AuraCMS 的Mod Block Statistik 存在远程脚本代码注入漏洞。远程攻击者可以通过stat操作中的HTTP 页眉中的X-Forwarded到达index.php来向online.db.txt的漏洞,注入任意PHP代码,并通过某个请求到达index.php来执行online.db.txt。
CVSS Information
N/A
Vulnerability Type
N/A