Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Unclassified NewsBoard abbc.css.php 目录遍历漏洞
Vulnerability Description
Unclassified NewsBoard (UNB) 1.5.3-d及可能的早期版本的bb_lib/abbc.css.php 存在目录遍历漏洞。启用register_globals时,可以使远程攻击者借助design_path参数(该参数中包含..)序列和尾随的零字节(%00),读取任意文件。注意:此漏洞与ABBC[Config][smileset]关系密切而有所不同。
CVSS Information
N/A
Vulnerability Type
N/A