漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Meizhou Qingyunke QYKCMS Update api.php unrestricted upload
Vulnerability Description
A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_system/api.php of the component Update Handler. The manipulation of the argument downurl leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223287.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Meizhou Qingyunke QYKCMS 代码问题漏洞
Vulnerability Description
Meizhou Qingyunke QYKCMS(青云客网站管理系统)是中国梅州市青云客网络科技(Meizhou Qingyunke)公司的一个网站管理系统。 Meizhou Qingyunke QYKCMS 4.3.0版本存在代码问题漏洞,该漏洞源于在/admin_system/api.php发现函数downurl()存在无限制的上传漏洞。
CVSS Information
N/A
Vulnerability Type
N/A