漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshell and achieve Remote Code Execution on the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Visitor Management System 安全漏洞
Vulnerability Description
Visitor Management System是一个访客管理系统。 Visitor Management System 1.0版本存在安全漏洞,该漏洞源于vms/php/admin_user_insert.php和vms/php/update_1.php文件上传功能缺乏验证,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A