PHP-Nuke Image Tag Admin Command...

- AV AC AU C I A
发布: 2004-03-16
修订: 2025-04-13

It has been reported that PHP-Nuke is prone to a remote admin command execution vulnerability. This issue is due to a design error that allows an attacker to specify arbitrary URI values in bbCode tags contained within posts. This issue may be leveraged to force an admin user viewing a malicious post to perform some query to the affected application such as adding a user or removing arbitrary data from the database.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息