漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Xerte Online Toolkits File Upload RCE via elfinder Connector
Vulnerability Description
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不完整的黑名单
Vulnerability Title
Xerte Online Toolkits 安全漏洞
Vulnerability Description
Xerte Online Toolkits是英国Xerte公司的一个在线学习内容制作平台。 Xerte Online Toolkits 3.15及之前版本存在安全漏洞,该漏洞源于elFinder连接器端点输入验证不完整,未能阻止.php4等PHP可执行扩展,未经身份验证的攻击者可利用此缺陷结合身份验证绕过和路径遍历漏洞上传恶意PHP代码,将其重命名为.php4扩展,并在服务器上执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A