Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Morfy CMS 代码注入漏洞
Vulnerability Description
Morfy CMS是软件开发者Sergey Romanenko所研发的一套轻量级的基于文件的内容管理系统(CMS)。 Morfy CMS 1.05版本的install.php脚本中存在静态代码注入漏洞。远程攻击者可借助‘site_url’参数利用该漏洞向config.php脚本中注入任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A