Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
baowzh hfly upload_json.php unrestricted upload
Vulnerability Description
A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_json.php. Performing manipulation of the argument imgFile results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
hfly 代码问题漏洞
Vulnerability Description
hfly是baowzh个人开发者的一个旅游网站。 hfly存在代码问题漏洞,该漏洞源于对文件/Public/Kindeditor/php/upload_json.php中参数imgFile的错误操作,可能导致任意文件上传。
CVSS Information
N/A
Vulnerability Type
N/A