tellmatic中存在多个PHP远程文件包含漏洞,远程攻击者可以借助include/中的(1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php,或(5) libchart-1.1/libchart.php的tm_includepath参数的URL执行任意PHP代码。
tellmatic中存在多个PHP远程文件包含漏洞,远程攻击者可以借助include/中的(1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php,或(5) libchart-1.1/libchart.php的tm_includepath参数的URL执行任意PHP代码。