Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244. NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpXplorer Action.PHP目录遍历漏洞
Vulnerability Description
phpXplorer的action.php中存在目录遍历漏洞,远程攻击者可以通过sAction参数中的".."(两点)序列和空字节读取任意文件,注意:phpXplorer功能支持上传PHP文件,则此问题将不会跨越特权边界,也就不是漏洞了。
CVSS Information
N/A
Vulnerability Type
N/A