Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Enalean Tuleap‘unserialize()’函数代码注入漏洞
Vulnerability Description
Enalean Tuleap是法国Enalean公司的一套开源的软件开发和项目管理工具。该工具提供企业应用程序生命周期管理,以及项目跟踪、源代码管理和团队协作等功能。 Enalean Tuleap 7.7之前版本的project/register.php脚本中存在安全漏洞。当程序禁用sys_create_project_in_one_step时,远程攻击者可利用该漏洞实施PHP对象注入攻击,并执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A