Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PhpList 代码问题漏洞
Vulnerability Description
PhpList是英国PhpList公司的一套开源的新闻通讯和电子邮件营销软件。 phplist 3.5.1存在安全漏洞,该漏洞源于应用程序不会检查插件 zip 文件中存储的任何文件扩展名。上传包含扩展名为 PHP、phtml、php7 的 php 文件的恶意插件将被复制到 plugins 目录,这将导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A