漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Multiple elFinder Plugins - Authenticated OS Command Injection
Vulnerability Description
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ninja Team File Manager Pro – Filester 代码注入漏洞
Vulnerability Description
Ninja Team File Manager Pro – Filester是Ninja Team团队的一款WP 文件管理器专业版插件。 Ninja Team File Manager Pro – Filester存在代码注入漏洞,该漏洞源于处理图像操作时未正确转义参数就传递给shell命令,可能导致经过身份验证的用户执行OS命令注入。以下产品及版本受到影响:FileOrganizer WordPress plugin 1.1.9之前版本、Advanced File Manager WordPress p
CVSS Information
N/A
Vulnerability Type
N/A