Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Asial JpGraph 安全漏洞
Vulnerability Description
Asial JpGraph是Asial公司的一个面向对象的 PHP 图形创建库。 Asial JpGraph 4.2.6-pro版本及之前版本存在安全漏洞。远程攻击者利用该漏洞通过 data 参数中的 PHP 载荷以及 filename 参数中的 .php 文件名执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A