Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
UCMS 代码注入漏洞
Vulnerability Description
UCMS是一套使用PHP语言编写的内容管理系统。 UCMS 1.4.6版本中的install/index.php文件存在代码注入漏洞。攻击者可借助systemdomain参数利用该漏洞注入并执行PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A