漏洞描述 在MySpace Content Zone (MCZ) 3.x中的admin/uploadgames.php不要求管理权限,这会允许远程攻击者无限制上传文件,例如(1)a .php文件(2)a .php%00.jpeg文件。
相关漏洞推荐 POC wp-ssl-insecure-content-fixer-fpd: WordPress Plugin SSL Insecure Content Fixer - Full Path Disclosure POC wp-table-of-contents-plus-fpd: WordPress Table of Contents Plus - Full Path Disclosure POC wp-toc-plus-fpd: WordPress Plugin Table of Contents Plus - Full Path Disclosure POC wp-ssl-insecure-content-fixer-fpd: WordPress Plugin SSL Insecure Content Fixer - Full Path Disclosure POC CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update POC weak-csp-detect: Weak Content Security Policy - Detect 孚盟云CRM /Ajax/GetDropDownListContent.ashx SQL 注入漏洞 孚盟云 GetDropDownListContent.ashx 存在SQL注入漏洞 POC 孚盟云 GetDropDownListContent.ashx SQL注入漏洞 cellinxnvt-getfilecontent-cgi-fileread: Cellinx NVT - GetFileContent.cgi - FileRead POC CVE-2014-5368: WordPress Plugin WP Content Source Control - Directory Traversal POC CVE-2017-10075: Oracle Content Server - Cross-Site Scripting POC CVE-2019-5418: Rails File Content Disclosure