search
HomeCMS TutorialPHPCMSThe most comprehensive summary of PHPCMS vulnerabilities

The most comprehensive summary of PHPCMS vulnerabilities

PHPCMS vulnerability summary is as follows:

1. Vulnerability name: Logic problem somewhere in phpcms Causes getshell

Patch file path: www/phpcms/libs/classes/attachment.class.php

Patch plan: https://www.php.cn/ cms/phpcms/436117.html

2. Vulnerability name: phpcms authkey generation algorithm problem leads to authkey leakage

Patch file path: www/caches/configs /system.php

Patch plan: https://www.php.cn/cms/phpcms/436123.html

3. Vulnerability name: phpcms front-end injection leads to arbitrary file reading vulnerability

Patch file path: www/phpcms/modules/content/down.php

Patch plan: https://www .php.cn/cms/phpcms/436128.html

4. Vulnerability name: phpcms SQL injection vulnerability file param.class.php

Patch File path: www/phpcms/libs/classes/param.class.php

Patch plan: https://www.php.cn/cms/phpcms/436133.html (No. Five)

5. Vulnerability name: phpcms v9 wide byte injection vulnerability

Patch file path: www/phpcms/modules/pay/respond.php

Patch plan: https://www.php.cn/cms/phpcms/436136.html

6. Vulnerability name: phpcms injection vulnerability file* poster.php *

Patch file path: www/phpcms/modules/poster/poster.php

Patch plan: https://www.php.cn/ cms/phpcms/436141.html

7. Vulnerability name: phpcms injection vulnerability file * phpsso.php *

Patch file path: www/api / phpsso.php

Patch plan: https://www.php.cn/cms/phpcms/436133.html (Article 7)

8. Vulnerability name: phpcms injection vulnerability file * index.php *

Patch file path: www/phpcms/modules/member/index.php

Patch plan: https://www.php.cn/cms/phpcms/436133.html (Article 4)

9. Vulnerability name: Other vulnerability tips

Patch file path: Please refer to the link on the right or other networks

Patch plan: https://www.php.cn/cms/phpcms/436133.html

PHP Chinese website, a large number of free PHPCMS tutorials, welcome to learn online!

This article is reproduced from: https://blog.csdn.net/qq_35393869/article/details/80653534

The above is the detailed content of The most comprehensive summary of PHPCMS vulnerabilities. For more information, please follow other related articles on the PHP Chinese website!

Statement
This article is reproduced at:CSDN. If there is any infringement, please contact admin@php.cn delete

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

mPDF

mPDF

mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

WebStorm Mac version

WebStorm Mac version

Useful JavaScript development tools

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver Mac version

Dreamweaver Mac version

Visual web development tools