Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dingfanzu 安全漏洞
Vulnerability Description
dingfanzu是gk2007个人开发者的一个基于 php 的外卖订餐网站。 dingfanzu V1.0版本存在安全漏洞,该漏洞源于通过组件 doAdminAction.php 的 addPro 参数发现包含跨站点请求伪造漏洞。远程攻击者利用该漏洞可以执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A