Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Nuke搜索字段路径泄露漏洞
Vulnerability Description
PHP-Nuke是一个广为流行的网站创建和管理工具,它可以使用很多数据库软件作为后端,比如MySQL、PostgreSQL、mSQL、Interbase、Sybase等。 PHP-Nuke没有正确处理用户提交的搜索请求,远程攻击者可以利用这个漏洞获得系统路径信息。 攻击者可以在搜索文本框中使用("') "和'字符,或使用"、>、'字符,提交搜索请求后,PHP-Nuke会返回包含安装路径的敏感信息。攻击者可以利用此信息对系统进行进一步攻击。
CVSS Information
N/A
Vulnerability Type
N/A