Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2) element.inc.php, and (3) node.inc.php, which leaks the path in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Limbo CMS 安装路径泄露漏洞
Vulnerability Description
远程攻击者可以借助Limbo CMS 1.0.4.2及更早版本,通过对(1) doc.inc.php、(2) element.inc.php和(3) node.inc.php的直接请求造成在错误信息中泄露路径,从而获得应用程序的安装路径。
CVSS Information
N/A
Vulnerability Type
N/A