Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Niti Telecom Caravan Business Server远程目录遍历漏洞
Vulnerability Description
Niti Telecom Caravan Business Server是一款基于WEB的服务程序。 Niti Telecom Caravan Business Server包含的showcode.asp脚本对用户提交的请求缺少充分过滤,远程攻击者可以利用这个漏洞以WEB权限查看系统文件。 使用包含多个'../'的转义字符作为参数提交给showcode.asp脚本,可绕过WEB ROOT目录限制,以WEB进程权限查看系统文件。
CVSS Information
N/A
Vulnerability Type
N/A