Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HorizontCMS 代码问题漏洞
Vulnerability Description
HorizontCMS是个人开发者的一个客户关系管理 Web 平台。 HorizontCMS 1.0.0-beta.3 之前存在安全漏洞,攻击者可通过使用媒体文件上传功能上传 .htaccess 和 *.hello 文件。
CVSS Information
N/A
Vulnerability Type
N/A