Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CitrusDB信用卡数据远程信息泄露漏洞
Vulnerability Description
CitrusDB是一个PHP开源客户关系维护和账单管理解决方案,CitrusDB主要功能有跟踪客户服务信息、安全级别设置、服务管理、产品以及账单发票、信用卡资料管理、模块定制、多语言发票印制、预付提醒等。 CitrusDB 0.3.5及更早版本在web根目录下存储newfile.txt临时文件,远程攻击者可以通过直接请求newfile.txt来偷窃信用卡信息。
CVSS Information
N/A
Vulnerability Type
N/A