PHPShop Remote PHP Script Execution...

- AV AC AU C I A
发布: 2004-05-10
修订: 2025-04-13

Reportedly phpShop is affected by a remote PHP script execution vulnerability. This issue is due to improper validation of user-supplied variables passed to the application via URI, POST or COOKIE parameters. This issue is present whether or not the PHP Apache module is configured with 'register_globals' turned off or on. This issue would allow an attacker to execute arbitrary PHP scripts on an affected host; issuing commands to the underlying operating system with the privileges of the web server is possible.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息