漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthenticated Remote Code Execution in SOY CMS
Vulnerability Description
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
SOY CMS 代码问题漏洞
Vulnerability Description
SOY CMS是一套内容管理系统(CMS)。 SOY CMS 3.0.2.327版本及之前版本存在安全漏洞。该漏洞源于没有任何限制地反序列化表单,攻击者可利用该漏洞远程代码执行(RCE)。
CVSS Information
N/A
Vulnerability Type
N/A