Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TeemIp 命令代码注入漏洞
Vulnerability Description
TeemIp 2.4.0之前版本中的exec.php文件的‘new_config’参数存在命令代码注入漏洞,该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
CVSS Information
N/A
Vulnerability Type
N/A