在 SPIP 4.4.20 之前的版本中,未经身份验证的远程攻击者可执行任意代码,此漏洞已在野外于 2026 年 8 月被利用。该问题与对 代码块的识别错误有关,同时 函数在处理某些特殊情况(例如存在 字符)时也存在处理不当的问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet