Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Iconify SkyBlueCanvas‘index.php’格式化字符串漏洞
Vulnerability Description
SkyBlueCanvas CMS是Iconify公司的一套轻量级Web内容管理系统。该系统使用XML存储数据,并提供主题、附加组件、问题报告等功能。 SkyBlueCanvas CMS 1.1 r248-03及之前的版本中的cms/data/skins/techjunkie/fragments/contacts/functions.php脚本中的‘bashMail’函数中存在安全漏洞,该漏洞源于index.php脚本中存在错误。当‘pid’参数设置为‘4’时,远程攻击者可借助(1)name、(2)ema
CVSS Information
N/A
Vulnerability Type
N/A