Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Icinga Web 2 安全漏洞
Vulnerability Description
Icinga Web 2是Icinga项目的一款基于PHP的响应式、可扩展的Web应用程序框架。 Icinga Web 2 2.6.1版本中存在安全漏洞。攻击者可利用该漏洞注入PHP ini-file指令,获取信息。
CVSS Information
N/A
Vulnerability Type
N/A