Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
webSPELL 'language.php' SQL注入漏洞
Vulnerability Description
webSPELL 4.2.0e版本及其早期版本的src/func/language.php中存在目录遍历漏洞。远程攻击者可以借助一个语言cookie中的一个..(参数中包含'..'),包含和运行任意本地.php文件。注意:该漏洞可以通过包含awards.php进一步扩大为SQL注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A