漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PHAR Deserialization in dompdf/dompdf
Vulnerability Description
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Dompdf 安全漏洞
Vulnerability Description
Dompdf是一个 HTML 到 PDF 的转换器。 Dompdf 存在安全漏洞,该漏洞源于容易受到使用反序列化不受信任数据的影响。
CVSS Information
N/A
Vulnerability Type
N/A