Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, leading to a denial of service.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
twittodon 安全漏洞
Vulnerability Description
twittodon是to3k个人开发者的一个网站页面。 twittodon b1c58a7d1dc664b38deb486ca290779621342c0b存在安全漏洞,该漏洞源于download.php脚本中obj参数反序列化不当,可能导致拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A