Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TomatoCMS任意文件上传漏洞
Vulnerability Description
TomatoCMS是一款开源的内容管理系统。 TomatoCMS 2.0.6以及早期版本存在未限制文件上传漏洞。具有某些权限的远程认证用户可以借助未明目录中的对一个文件的直接请求上传图形文件,执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A