Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Visual Studio Code 命令注入漏洞
Vulnerability Description
Microsoft Visual Studio Code是美国微软(Microsoft)公司的一款开源的代码编辑器。 Visual Studio Code 1.3.0之前版本存在安全漏洞,该漏洞源于Visual Studio Code 的非官方vcode -phpmd(又名PHP混乱探测器)扩展存在问题。攻击者可利用该漏洞通过特制的phpmd.command值执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A