在 HortusFox 6.2 版本之前,ThemeModule::startImport() 函数中存在远程代码执行漏洞。该漏洞源于系统在执行任何文件名、扩展名或内容验证之前,直接将上传的 ZIP 归档文件解压至公共 Web 根目录。经过身份验证的管理员可以上传一个精心构造的主题归档文件,其中包含 PHP 文件和 .htaccess 文件,以重新启用 PHP 执行功能,随后通过请求 themes 目录下的该文件,即可以 Web 服务器用户的身份执行任意操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| danielbrendel | hortusfox-web | 0 ~ 6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet