Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Megacubo URI处理器远程命令执行漏洞
Vulnerability Description
Megacubo是用PHP和Winbinder编写的IPTV应用程序。 Megacubo的mega:// uri处理器没有正确地验证通过play命令所传送的参数,如果远程攻击者提交了带有con(设备名称)参数的play命令的话,就可以绕过file_exists()检查将恶意参数拷贝到c:\DATASTORE.txt文件并执行。
CVSS Information
N/A
Vulnerability Type
N/A