Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Leszek Krupinski L-Forum文件泄露漏洞
Vulnerability Description
L-Forum 2.40以及之前版本不能正确验证是否上传文件或者POST是否设置相关变量(附件,附件名,附件大小,附件类型)。远程攻击者读取任意变量。
CVSS Information
N/A
Vulnerability Type
N/A