Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vBSEO ‘proc_deutf()’ 远程代码执行漏洞
Vulnerability Description
vBSEO中的includes/functions_vbseocp_abstract.php中的proc_deutf函数中存在远程代码执行漏洞。攻击者可利用此漏洞在受影响应用程序上下文中执行任意代码。vBSEO 3.5.0版本、3.5.1版本、 3.5.2版本和 3.6.0.版本中存在漏洞,其它版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A