Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Emlog vulnerable to Deserialization of Untrusted Data
Vulnerability Description
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserialization to fail and return `false`. Commit 9643250802188b791419e3c2188577073256a8a2 fixes the issue.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
emlog 代码问题漏洞
Vulnerability Description
emlog是emlog开源的一套基于PHP和MySQL的CMS建站系统。 emlog 2.5.13及之前版本存在代码问题漏洞,该漏洞源于反序列化漏洞,可能导致反序列化失败。
CVSS Information
N/A
Vulnerability Type
N/A