Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE
Vulnerability Description
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
magicblack maccms10 代码注入漏洞
Vulnerability Description
magicblack maccms10是magicblack个人开发者的一款内容管理系统。 magicblack maccms10存在代码注入漏洞,该漏洞源于管理员模板编辑器通过黑名单正则阻止危险PHP函数,但黑名单遗漏了exec、passthru、popen、show_source、create_function、register_shutdown_function、register_tick_function和error_log,结合ThinkPHP的{if}模板标签将条件属性直接嵌入原始PHP,可能
CVSS Information
N/A
Vulnerability Type
N/A