# 源代码战士酒店系统管理上传漏洞
## 概述
在 SourceCodester Hotel and Lodge Management System 1.0 及以下版本中发现一个安全漏洞。
## 影响版本
- SourceCodester Hotel and Lodge Management System ≤ 1.0
## 细节
- 漏洞文件:`/manage_website.php`
- 漏洞参数:`website_image` / `back_login_image`
- 漏洞类型:任意文件上传(Unrestricted Upload)
- 攻击方式:远程利用(Remote)
## 影响
该漏洞可被远程攻击者利用,上传恶意文件,可能导致服务器被控制或网站数据被篡改。目前该漏洞已被公开披露,存在被实际利用的风险。
# | POC 描述 | 源链接 | 神龙链接 |
---|
标题: File Upload vulnerability from sourcecodester Hotel and Lodge Management System using PHP with Source Code V1.0 /manage_website.php · Issue #13 · TThuyyy/cve1 -- 🔗来源链接
标签: exploit issue-tracking
标题: Free Source Code Projects and Tutorials - sourcecodester.com -- 🔗来源链接
标签: product
标题: Login required -- 🔗来源链接
标签: signature permissions-required
标题: Submit #665462: SourceCodester Hotel and Lodge Management System 1.0 Unrestricted Upload -- 🔗来源链接
标签: third-party-advisory
标题: CVE-2025-11470 SourceCodester Hotel and Lodge Management System manage_website.php unrestricted upload -- 🔗来源链接
标签: vdb-entry technical-description
暂无评论