漏洞标题
N/A
漏洞描述信息
在BasiliX 1.1.1 早期版本中,存在多个 PHP 远程文件包含漏洞,允许远程攻击者通过在 /files/ 脚本中的 BSX_LIBDIR 参数中的 URL 执行任意 PHP 代码,包括 (a) abook.php3,(b) compose-attach.php3,(c) compose-menu.php3,(d) compose-new.php3,(e) compose-send.php3,(f) folder-create.php3,(g) folder-delete.php3,(h) folder-empty.php3,(i) folder-rename.php3,(j) folders.php3,(k) mbox-action.php3,(l) mbox-list.php3,(m) message-delete.php3,(n) message-forward.php3,(o) message-header.php3,(p) message-print.php3,(q) message-read.php3,(r) message-reply.php3,(s) message-replyall.php3,(t) message-search.php3,或(u) settings.php3;以及 (2) files/login.php3 中的 BSX_HTXDIR 参数。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f) folder-create.php3, (g) folder-delete.php3, (h) folder-empty.php3, (i) folder-rename.php3, (j) folders.php3, (k) mbox-action.php3, (l) mbox-list.php3, (m) message-delete.php3, (n) message-forward.php3, (o) message-header.php3, (p) message-print.php3, (q) message-read.php3, (r) message-reply.php3, (s) message-replyall.php3, (t) message-search.php3, or (u) settings.php3; and the (2) BSX_HTXDIR parameter in (v) files/login.php3.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
BasiliX 多个PHP远程文件包含漏洞
漏洞描述信息
BasiliX中存在多个PHP远程文件包含漏洞。远程攻击者通过以下方式执行任意PHP代码: /files/下脚本中的(1)BSX_LIBDIR参数内的URL,这些脚本包括:(a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f) folder-create.php3, (g) folder-delete.php3, (h) folder-e
CVSS信息
N/A
漏洞类别
授权问题