Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php, (e) Mail/mimeDecode.php, (f) Console/Getopt.php, (g) System.php, (h) Log.php, and (i) File.php in includes/pear/; the CONFIG[pear_dir] parameter to (j) includes/prepend.php, and (k) includes/cachedConfig.php; and the (2) CONFIG[includes] parameter to (l) prepend.php and (m) email.list.search.php in includes/. NOTE: the CONFIG[pear_dir] parameter to includes/mailaccess/pop3.php is already covered by CVE-2006-2666.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Christof_Bruyland V-webmail多个远程文件漏洞
Vulnerability Description
V-webmail 1.6.4版本中的多个PHP远程文件包含漏洞,该漏洞允许远程攻击者通过在CONFIG[pear_dir]参数和CONFIG[pear_dir]参数中的URL执行任意的PHP代码。 CONFIG[pear_dir]参数包括:(1)到(a)Mail/RFC822.php,(b) Net/Socket.php,(c) XML/Parser.php,(d) XML/Tree.php,(e) Mail/mimeDecode.php,(f)Console/Getopt.php,(g) System
CVSS Information
N/A
Vulnerability Type
N/A