Dayrui FineCms是中国天睿(Dayrui)程序设计团队发布的一套使用MVC架构和PDO数据库接口开发的内容管理系统(CMS)。 dayrui FineCms 5.2.0版本中的v5/config/system.php文件存在安全漏洞,该漏洞源于程序使用了默认的SYS_KEY值,并且对每次的安装没有要求重新生成密钥。远程攻击者可利用该漏洞上传任意的.php文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-3934 | Fiyo CMS SQL注入漏洞 | |
| CVE-2017-16664 | Open Ticket Request System 代码注入漏洞 | |
| CVE-2017-16923 | 多款Shenzhen Tenda产品命令注入漏洞 | |
| CVE-2017-15044 | DocuWare Fulltext Search server 安全漏洞 | |
| CVE-2017-16613 | OpenStack Swauth 安全漏洞 | |
| CVE-2017-16840 | FFmpeg VC-2 Video Compression解码器安全漏洞 | |
| CVE-2017-16919 | MapOS 跨站脚本漏洞 |
No comments yet