漏洞标题
N/A
漏洞描述信息
Der Dirigent (DeDi) 1.0.3 中的多个 PHP 远程文件包含漏洞允许远程攻击者通过(1)find.php,(2)insert_line.php,(3)fullscreen.php,(4)changecase.php,(5)insert_link.php,(6)insert_table.php,(7)table_cellprop.php,(8)table_prop.php,(9)table_rowprop.php,(10)insert_page.php,以及(11)backend/external/wysiswg/popups/中的cfg_dedi[dedi_path]参数中的 URL 执行任意 PHP 代码。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Multiple PHP remote file inclusion vulnerabilities in Der Dirigent (DeDi) 1.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_dedi[dedi_path] parameter in (1) find.php, (2) insert_line.php, (3) fullscreen.php, (4) changecase.php, (5) insert_link.php, (6) insert_table.php, (7) table_cellprop.php, (8) table_prop.php, (9) table_rowprop.php, (10) insert_page.php, and possibly insert_marquee.php in backend/external/wysiswg/popups/.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Der Dirigent 多个PHP远程文件包含漏洞
漏洞描述信息
Der Dirigent (DeDi) 1.0.3中存在多个PHP远程文件包含漏洞,远程攻击者可以通过(1)find.php,(2)insert_line.php,(3)fullscreen.php,(4)changecase.php,(5)insert_link.php,(6)insert_table.php,(7)table_cellprop.php,(8)table_prop.php,(9)table_rowprop.php,(10)insert_page.php和可能backend/externa
CVSS信息
N/A
漏洞类别
代码注入