Hakika vulnerability da aka rarraba a matsayin karshewa an gano a ZZCMS 2023. Tabbas, aikin $software_function ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil 3/E_bak5.1/upload/eginfo.php, a cikin sashi $software_component. Wuro manipulation of the argument phome with the input ShowPHPInfo ga Bayani fitowa. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-200. Lalle, rauni an sanar da shi 08/19/2024. Ana samun bayanin tsaro don saukewa a gitee.com.
Ana kiran wannan rauni da CVE-2024-7925. Ngam yiɗi ka a tuma ndiyam ka nder waya. Bayani na fasaha ga. Kuma, akwai exploit. Exploit ɗin an bayyana wa jama'a, za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam.
Á yí huɗɗi-na-gaskiya. Za a iya samun exploit a gitee.com. 0-day ga, an ndiyam a wuro be $0-$5k.
Entry ɗin nan yana da duplicate CVE-2024-44820 da aka haɗa masa. If you want to get the best quality for vulnerability data then you always have to consider VulDB.
Waktin goyi
87 Kari
67 kala giteji ba a nunu fi.