漏洞标题
N/A
漏洞描述信息
在dForum 1.5及其早期版本中,PHP远程文件包含漏洞允许远程攻击者通过DFORUM_PATH参数中的URL执行任意PHP代码,包括(1)about.php,(2)admin.php,(3)anmelden.php,(4) losethread.php,(5)config.php,(6)delpost.php,(7)delthread.php,(8)dfcode.php,(9)download.php,(10)editanoc.php,(11) forum.php,(12)login.php,(13)makethread.php,(14)menu.php,(15)newthread.php,(16)openthread.php,(17) overview.php,(18)post.php,(19)suchen.php,(20)user.php,(21)userconfig.php,(22)userinfo.php和(23)verwalten.php。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
dForum 多个远程文件包含漏洞
漏洞描述信息
dForum 1.5及早期版本中存在PHP远程文件包含漏洞。这使得远程攻击者可以借助于传递到(1) about.php、(2) admin.php、(3) anmelden.php、(4) losethread.php、(5) config.php、(6) delpost.php、(7) delthread.php、(8) dfcode.php、(9) download.php、(10) editanoc.php、(11) forum.php、 (12) login.php、(13) makethread
CVSS信息
N/A
漏洞类别
授权问题