漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Educational System 'CONF_INCLUDE_PATH'参数多个远程文件包含漏洞
Vulnerability Description
Open Education System (OES)存在多个PHP远程文件包含漏洞,远程攻击者可以借助多个脚本的CONF_INCLUDE_PATH的URL执行任意的PHP代码。这些脚本包含:admin/modules/modules/中的(1)forum/admin.php和(2)plotgraph/index.php;admin/modules/user_account/中的(3)admin_user/mod_admuser.php和(4)ogroup/mod_group.php。
CVSS Information
N/A
Vulnerability Type
N/A