漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LibrettoCMS File Manager Arbitrary File Upload
Vulnerability Description
An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Sourceforge LibrettoCMS 安全漏洞
Vulnerability Description
Sourceforge LibrettoCMS是Sourceforge开源的一款内容管理系统。 Sourceforge LibrettoCMS 1.1.7及之前版本存在安全漏洞,该漏洞源于文件管理器插件未正确验证文件扩展名,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A