Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AlegroCart 安全漏洞
Vulnerability Description
AlegroCart是加拿大ALEGROCART团队的一套开源的在线业务解决方案。 AlegroCart 1.2.8版本中的upload/admin2/controller/report_logs.php文件的‘get_file’函数存在远程文件包含漏洞,该漏洞源于程序没有检测‘file_path’参数。远程攻击者可利用该漏洞执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A