Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KeyFocus KF Web Server远程目录遍历漏洞
Vulnerability Description
KeyFocus Web服务程序是一款多功能的HTTP服务程序,支持多种日志格式,目录索引,预定义MIME设置,URL检查等功能。 KeyFocus Web服务程序不正确处理文件名包含'.'字符的请求,远程攻击者可以利用这个漏洞进行目录遍历攻击。 攻击者提交多个'.'字符的WEB请求,可导致脱离WEB ROOT目录,而以WEB进程的权限遍历系统目录,查看任意可查看的敏感文件内容。
CVSS Information
N/A
Vulnerability Type
N/A