STG Security Advisory 2005-08-12.27...

- AV AC AU C I A
发布: 2005-08-14
修订: 2025-04-13

STG Security Advisory: Discuz! does not properly check extensions of uploaded files, so malicious attackers can upload a file with multiple extensions such as attach.php.php.php.php.rar to a web server. This can be exploited to run arbitrary commands with the privilege of the HTTPD process, which is typically run as the nobody user. Versions 4.0.0 rc4 and prior are affected.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息