Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPKit目录遍历漏洞
Vulnerability Description
PHPKIT 1.6.1 R2及更早版本存在目录遍历漏洞, 远程认证用户可能通过一个路径参数中的..(参数中包含'..')和文件名尾的%00来执行任意PHP代码,如一个以.png%00结尾的头像文件名。
CVSS Information
N/A
Vulnerability Type
N/A