Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
X-Forum 'SaveConfig.php' SQL注入漏洞
Vulnerability Description
X-Forum是一个开放源码的Web公告板系统。 X-Forum 0.6.2版本中存在静态代码注入漏洞。远程认证管理员可以借助对SaveConfig.php的adminEMail参数,向Config.php注入任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A