Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
X7 Chat‘lib/message.php’代码注入漏洞
Vulnerability Description
X7 Chat是一款基于PHP的在线聊天程序。 X7 Chat 2.0.0版本至2.0.5.1版本的lib/message.php脚本中的‘preg_replace’函数存在安全漏洞。远程攻击者可借助index.php脚本的特制HTTP头利用该漏洞执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A