Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joomla! 安全漏洞
Vulnerability Description
Joomla!是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla! 2.5.0版本至3.8.8版本中存在本地文件包含漏洞,该漏洞源于在PHP 5.3版本中,‘class_exists’函数将无效的用户名验证为有效。攻击者可利用该漏洞获取敏感信息或在Web服务器进程的上下文中执行任意的本地脚本。
CVSS Information
N/A
Vulnerability Type
N/A