漏洞标题
源代码者科技产品在线订购系统产品不限范围上传
漏洞描述信息
源代码专家Gadget Works在线订购系统产品无限上传
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
SourceCodester Gadget Works Online Ordering System Products unrestricted upload
漏洞描述信息
A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/products/controller.php?action=add of the component Products Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223215.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
漏洞类别
危险类型文件的不加限制上传
漏洞标题
Online Ordering System 代码问题漏洞
漏洞描述信息
Online Ordering System是janobe个人开发者的一个多商店订购系统。可用于任何小型企业。 SourceCodester Gadget Works Online Ordering System 1.0版本存在代码问题漏洞,该漏洞源于组件Products Handler的文件 admin/products/controller.php?action=add 存在未知函数,通过 参数filename导致不受限制的上传。
CVSS信息
N/A
漏洞类别
代码问题