漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Achievo mcpuk文件编辑器'config.php' 未限制文件上传漏洞
Vulnerability Description
Achievo 1.2.0到1.3.2版本中的mcpuk文件编辑器(atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php)存在未限制文件上传漏洞。远程攻击者可以通过先上传一个带有安全扩展名的.php的文件,再借助对存档文件根目录中的文件的一个直接请求来访问它,从而实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A