Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Andy's PHP Projects 手册页lookup脚本信息泄露漏洞
Vulnerability Description
Andy's PHP Projects包含多个脚本程序,其中一个是手册页查询脚本。 手册页查询脚本没有正确处理用户提交参数,远程攻击者可以利用这个漏洞以Web进程权限查看系统文件内容。 问题是Man页管理脚本包含的index.php对用户提交给'command'参数的数据确实正确处理,攻击者可以提交任意系统文件,以WEB进程权限查看。
CVSS Information
N/A
Vulnerability Type
N/A