Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
TellMe 1.2 and earlier, when the Server (o_Server) and HEAD (o_Head) options are enabled, allows remote attackers to obtain sensitive information via an invalid q_Host parameter, which reveals the full pathname of the application in an fsockopen error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TellMe 敏感信息泄露漏洞
Vulnerability Description
TellMe 1.2及更早版本,在启用Server (o_Server)和HEAD (o_Head)选项时,远程攻击者可通过一个无效的q_Host参数使得fsockopen错误信息中泄露应用程序的完整路径,从而获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A