Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WikyBlog 'index.php/Attach'未限制文件上传漏洞
Vulnerability Description
WikyBlog是一款采用PHP和MySQL开发的Bliki CMS(即wiki+blog的内容管理系统),并且利用了AJAX强化的构造。该系统支持UTF-8字符集,拥有强大的可扩展性(如google map等)。 WikyBlog的脚本index.php/Attach中存在未限制文件上传漏洞。远程认证用户可以借助userfiles/[username]/uploaded/中的一个文件的直接请求,执行上传的可执行文件的任意代码。
CVSS Information
N/A
Vulnerability Type
N/A