Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CuteNews index.php安装路径信息泄露漏洞
Vulnerability Description
Cutenews是一款功能强大的新闻管理系统,使用二维表格式文本文件存储数据。 CuteNews 1.4.0及更早版本中的index.php,可让远程攻击者通过触发错误消息,例如在归档参数中输入多个../(两点和正斜杠),来获取应用程序的安装路径。
CVSS Information
N/A
Vulnerability Type
N/A