Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Owl's Workshop多个远程文件泄露漏洞
Vulnerability Description
OWLS 1.0版本存在漏洞。远程攻击者可以借助存在于(1)/glossaries/index.php的文件参数,(2)/readings/index.php的文件名参数或(3)/multiplechoice/resultsignore.php的文件名参数中的绝对路径名来检索任意文件,正如使用/etc/passwd。
CVSS Information
N/A
Vulnerability Type
N/A