PHP Todo List Manager 库文件规则表达式未明安全绕行漏洞

漏洞信息详情

PHP Todo List Manager 库文件规则表达式未明安全绕行漏洞

漏洞简介

phpTodo 中存在未明漏洞。远程攻击者可以借助对libs/中的(1)index.php,(2)feed.php,(3)prefs.php和(4)todolist.php,(5) classTodoItem.php和(6)phpTodoUser.php文件的表达式,造成未知影响。

漏洞公告

参考网址

External Source: VUPEN

Name: ADV-2007-1774

Type: Advisory; Patch Information

Hyperlink:http://www.frsirt.com/english/advisories/2007/1774

External Source: CONFIRM

Name: http://phptodo.godshell.com/ChangeLog

Type: Patch Information

Hyperlink:http://phptodo.godshell.com/ChangeLog

External Source: XF

Name: phptodo-regular-expression-security-bypass(34275)

Hyperlink:http://xforce.iss.net/xforce/xfdb/34275

External Source: BID

Name: 23928

Hyperlink:http://www.securityfocus.com/bid/23928

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享