Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DeluxeBB SQL注入和PHP注入漏洞
Vulnerability Description
DeluxeBB是一款基于PHP的论坛程序。 通过$REQUEST_URI注入并执行任意PHP代码。以下是有漏洞的代码段: 29.if($settings['cplog']==1 || $logs==1) { 30.$time = time(); 31.$dir = $settings['logpath']; 32.@chmod($dir.'/cp.php', 0777); 33.$string = $_COOKIE['membercookie'].""|##|$ip|##|$time|##|$REQUE
CVSS Information
N/A
Vulnerability Type
N/A