漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE)
Vulnerability Description
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP without passing them through expression(). An attacker who can influence Volt template source can place quote-breaking content in a join argument, inject PHP into the compiled cache file, and execute it when Phalcon\Mvc\View\Engine\Volt::render() loads the template. This issue is fixed in version 5.16.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Phalcon 代码注入漏洞
Vulnerability Description
Phalcon是phalcon公司开源的一款Web中间件。 Phalcon 5.15.0及之前版本存在代码注入漏洞,该漏洞源于phalcon/Mvc/View/Engine/Volt/Compiler.zep中的resolveFilter函数将原始分隔符和数组令牌值直接插入生成的PHP中,可能导致攻击者通过影响Volt模板源码注入PHP到编译缓存文件并执行。
CVSS Information
N/A
Vulnerability Type
N/A