Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
烟火网络科技 SDCMS 跨站请求伪造漏洞
Vulnerability Description
烟火网络科技 SDCMS是中国烟火网络科技公司的一套基于PHP和MySQL的企业建站内容管理系统(CMS)。 烟火网络科技 SDCMS 1.7版本中存在跨站请求伪造漏洞。远程攻击者可通过借助‘file’和‘t2’参数发送文件名和文件内容利用该漏洞执行PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A