漏洞标题
N/A
漏洞描述信息
在phpCMS 1.2.1pl2中有多个PHP远程文件包含漏洞,允许远程攻击者通过PHPCMS_INCLUDEPATH参数中的URL执行任意PHP代码,包括(1)类.parser_phpcms.php,(2)类.session_phpcms.php,(3)类.edit_phpcms.php,(4)类.http_indexer_phpcms.php,(5)类.cache_phpcms.php,(6)类.search_phpcms.php,(7)类.lib_indexer_universal_phpcms.php,和(8)类.layout_phpcms.php,(9)类.parser/plugs/counter.php,(10)类.parser/parser.php。请注意:类.cache_phpcms.php向量也被报告 affecting 1.1.7。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
phpCMS 多个PHP远程文件包含漏洞
漏洞描述信息
phpCMS 1.2.1pl2存在多个PHP远程文件包含漏洞。远程攻击者可以借助对包括(1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_ph
CVSS信息
N/A
漏洞类别
代码注入