在 SPIP 4.4.21 之前的版本中,未认证的远程攻击者可以利用此漏洞执行任意代码,该漏洞已于 2026 年 8 月在野被利用。此漏洞与通过 X-Spip-Filtre HTTP 请求头进行的代码注入有关,而 analyse_resultat_skel 函数对此头部的处理存在缺陷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet