InstantCMS 是一款免费且开源的内容管理系统。在 2.18.2 之前的版本中存在远程代码执行(RCE)漏洞,允许经过身份验证的远程攻击者通过组件安装器执行任意 PHP 代码。攻击者可以将一个恶意组件上传至服务器,虽然该组件不会被安装,但上传的文件会被执行。通常,上传目录中的所有 PHP 文件默认不会被执行,但通过上传自定义的 文件,可以使这些文件得以执行。版本 2.18.2 已包含对该漏洞的修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| instantsoft | icms2 | < 2.18.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| instantsoft | icms2 | < 2.18.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet