Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SimpleBBS posts.php 目录遍历漏洞
Vulnerability Description
SimpleBBS 1.0.6至1.0.6中的posts.php存在目录遍历漏洞。这使得远程攻击者可以借助于语言cookie(cookie中的包含..)序列包含并执行任意文件,例如将代码注入到user.php中的gl_session cookie中,上述程存储在error.log中。
CVSS Information
N/A
Vulnerability Type
N/A