Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FlatNuke 敏感信息泄露漏洞
Vulnerability Description
FlatNuke 2.5.3存在安全漏洞,远程攻击者可通过:(1) 向foot_news.php发送直接请求引起无限循环,或 (2) 向未知脚本发送直接请求,来触发拒绝服务攻击,或者获取敏感信息。这些请求会在出错信息中泄漏web文档根目录。
CVSS Information
N/A
Vulnerability Type
N/A