漏洞标题
云悠悠CMS/Common.php无限制上传
漏洞描述信息
云游CMS 2.2.6及以下版本存在一个已分类为“严重”的漏洞。此漏洞影响文件/app/index/controller/Common.php中未知代码。通过操纵参数templateFile,会导致不受限制的上传。此攻击可以远程执行。该漏洞已向公众披露,可能被利用。VDB-251374是此漏洞的标识符。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
危险类型文件的不加限制上传
漏洞标题
Yunyou CMS Common.php unrestricted upload
漏洞描述信息
A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The manipulation of the argument templateFile leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251374 is the identifier assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
危险类型文件的不加限制上传
漏洞标题
YUNUCMS 代码问题漏洞
漏洞描述信息
YUNUCMS是一个网站CMS。 YUNUCMS 2.2.6及之前版本存在代码问题漏洞,该漏洞源于文件/app/index/controller/Common.php的参数 templateFile存在任意文件上传漏洞。
CVSS信息
N/A
漏洞类别
代码问题