Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Chyrp swfupload扩展upload_handler.php权限许可和访问控制漏洞
Vulnerability Description
Chyrp是一款开源的基于PHP和MySQL的轻量级博客(Blog)引擎。 Chyrp 2.0及早期版本的swfupload扩展中的upload_handler.php依赖客户端JavaScript代码限制上传文件的扩展。远程认证用户可借助对admin/下默认URI的write_post操作上传.php文件并执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A