Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SeaCMS 安全漏洞
Vulnerability Description
SeaCMS是海洋CMS(SeaCMS)公司的一套使用PHP编写的免费、开源的网站内容管理系统。该系统主要被设计用来管理视频点播资源。 SeaCMS 12.9版本存在安全漏洞,该漏洞源于admin_config_mark. php直接将用户输入数据拼接写入inc_photowatermark_config.php而不进行处理,经过身份验证的攻击者利用该漏洞可以执行任意命令并获得系统权限。
CVSS Information
N/A
Vulnerability Type
N/A