Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a hidden_req POST parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gazie 安全漏洞
Vulnerability Description
Gazie是一款基于PHP和MySQL的财务应用程序。该程序支持发票管理、库存管理和订单管理等功能。 Gazie 7.32版本中存在安全漏洞。攻击者可借助‘hidden_req’参数利用该漏洞包含任意的PHP文件。
CVSS Information
N/A
Vulnerability Type
N/A