Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
UltimatePOS 安全漏洞
Vulnerability Description
UltimatePOS是一套销售管理系统。该系统支持库存管理、销售管理和发票管理等功能。 UltimatePOS 2.5版本中存在安全漏洞。攻击者可通过向/products URI发送内容类型为image/jpeg并且.php文件中带有PHP代码的POST请求利用该漏洞上传任意文件,执行命令。
CVSS Information
N/A
Vulnerability Type
N/A