Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
gps-server.net GPS Tracking Software(self hosted)安全漏洞
Vulnerability Description
gps-server.net GPS Tracking Software(self hosted)是一款GPS定位跟踪程序。该程序能够管理跟踪历史、报告、事件和通知等。 gps-server.net GPS Tracking Software(self hosted)3.0及之前的版本中的fn_common.php文件的‘writeLog’函数存在安全漏洞。远程攻击者可通过发送特制的请求利用该漏洞注入任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A