Joomla OpenSEF Component...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Joomla OpenSEF是一款基于PHP的WEB应用程序。 Joomla OpenSEF不正确过滤用户提交的URI数据,远程攻击者可以利用漏洞以WEB进程权限执行任意命令。 问题是'sef.php'脚本对用户提交的'mosConfig_absolute_path'参数缺少过滤,提交恶意的远程服务器作为包含对象,可导致以WEB进程权限执行任意PHP代码。 OpenSEF Project OpenSEF 2.0-beta3 OpenSEF Project OpenSEF 2.0 RC5 SP2 OpenSEF Project OpenSEF 2.0 RC5 SP1 OpenSEF Project OpenSEF 2.0 RC5 OpenSEF Project OpenSEF 2.0 RC4 OpenSEF Project OpenSEF 2.0 RC3 OpenSEF Project OpenSEF 2.0 RC2 OpenSEF Project OpenSEF 2.0 RC1 <a href="http://www.open-sef.org/" target="_blank">http://www.open-sef.org/</a>

0%
暂无可用Exp或PoC
当前有0条受影响产品信息