Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Matt Wright FormHandler.cgi脚本默认配置漏洞
Vulnerability Description
Matt Wright FormHandler.cgi脚本的默认配置允许附件使用任意目录,并且只对/etc/ directory限制访问。远程攻击者可以通过reply_message_attach附件参数读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A