Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
YouDianCMS ydLib.php curl_exec server-side request forgery
Vulnerability Description
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
YouDianCMS 代码问题漏洞
Vulnerability Description
YouDianCMS(友点CMS)是中国友点(YouDian)公司的一个建站网站。 YouDianCMS 7版本存在代码问题漏洞,该漏洞源于文件curl_exec /App/Core/Extend/Function/ydLib.php的参数url会导致服务器端请求伪造。
CVSS Information
N/A
Vulnerability Type
N/A