Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LuLu CMS 安全漏洞
Vulnerability Description
LuLu CMS是一套基于Yii Framework开发的一套内容管理系统(CMS)。 LuLu CMS 2015-05-14及之前版本中的backend\modules\filemanager\controllers\DefaultController.php文件存在安全漏洞。攻击者可通过在文本输入字段中输入文件名、目录名和PHP代码利用该漏洞上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A