Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Just Another Flat文件(JAF) CMS错误消息泄露漏洞
Vulnerability Description
Just Another Flat文件(JAF) CMS 3.0RC版本中config.php的displaycontent函数存在漏洞。远程攻击者可以借助空的show参数获得敏感信息,该漏洞在错误消息中泄露了安装路径,正如使用index.php。
CVSS Information
N/A
Vulnerability Type
N/A