Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpMyBackupPro 安全漏洞
Vulnerability Description
phpMyBackupPro是一套免费的基于Web的MySql备份工具。该工具支持自动备份、定时备份、异地备份MySql数据库。 phpMyBackupPro 2.5及之前的版本中存在安全漏洞。远程攻击者可通过向scheduled.php文件发送‘path’、‘filename’和‘dirs’参数利用该漏洞注入和执行任意的PHP脚本。
CVSS Information
N/A
Vulnerability Type
N/A