Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CoolForum远程源代码泄露漏洞
Vulnerability Description
CoolForum是一款由PHP编写基于WEB的论坛程序。 CoolForum中的'avatar.php'脚本对用户提交请求缺少充分检查,远程攻击者可以利用这个漏洞访问任意PHP文件源代码,包括受限目录中的文件。 论坛程序中包含的'avatar.php'脚本用于显示存储在'logos'目录中的图象文件,下面是avatar.php的源代码: <? header('Pragma: no-cache'); if (ereg(".jpg",$img)) header("Content-Type: image/jp
CVSS Information
N/A
Vulnerability Type
N/A