Froxlor是Froxlor团队的一套轻量级服务器管理软件。 Froxlor 2.3.6之前版本存在代码注入漏洞,该漏洞源于PhpHelper::parseArrayToString()在写入单引号PHP字符串字面量时未转义单引号,且privileged_user参数无输入验证,导致攻击者可以注入任意PHP代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41228 | 10.0 CRITICAL | Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that l |
| CVE-2026-41230 | 8.5 HIGH | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones:: |
| CVE-2026-41231 | 7.5 HIGH | Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Director |
| CVE-2026-41233 | 5.4 MEDIUM | Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.ad |
| CVE-2026-41232 | 5.0 MEDIUM | Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allow |
No comments yet