Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a config.php file, hosting the .zip file at an external URL, and visiting index.php?r=appmanage/index/onlineinstall&url= followed by that URL. This is related to the onlineinstall and import functions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
YXcms 安全漏洞
Vulnerability Description
YXcms是一套基于PHP和MySQL的企业建站内容管理系统(CMS)。 YXcms 1.4.7版本中的protected/apps/appmanage/controller/indexController.php文件存在安全漏洞。远程攻击者可借助一个带有config.php文件的ZIP归档文件利用该漏洞执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A