Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zeroo HTTP Server远程目录遍历漏洞
Vulnerability Description
Zeroo HTTP Server是一款简单快速的WEB服务器程序。 Zeroo HTTP对用户提交的恶意WEB请求缺少正确过滤,远程攻击者可以利用这个漏洞以WEB进程权限查看系统上任意文件内容。 由于Zeroo不正确过滤WEB请求,攻击者可以提交包含多个'../'的WEB请求给Zeroo服务程序,可绕过WEB ROOT目录的限制,以WEB权限查看系统上任意文件内容。造成敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A