YaBB SE News.PHP Remote File Include...

- AV AC AU C I A
发布: 2003-01-24
修订: 2025-04-13

A vulnerability has been discovered in YaBB SE. Due to insufficient sanitization of some user-supplied variables by the 'News.php' script, it is possible for a remote attacker to include a malicious PHP file in a URL. By placing a script on an attacker-controlled host and mimicking the name and directory structure of the server, it is possible to cause a vulnerable server to include the attacker-supplied PHP script file.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息