Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpNewsManager functions.php脚本文件泄露漏洞
Vulnerability Description
PhpNewsManager是一款基于WEB的新闻管理程序。 PhpNewsManager包含的functions.php脚本对提交的参数数据缺少充分过滤,远程攻击者可以利用这个漏洞以WEB进程权限在系统上查看任意文件内容。 提交包含多个'../'字符的数据作为functions.php脚本的'clang'数据,可绕过WEB ROOT限制,以WEB进程权限在系统上查看任意文件内容。
CVSS Information
N/A
Vulnerability Type
N/A