Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Andrew Godwin ByteHoard index.php 绝对路径遍历漏洞
Vulnerability Description
Andrew Godwin ByteHoard 2.1及之前版本的index.php中的复制操作中存在绝对路径遍历漏洞。远程认证用户可以通过指定infolder参数中的目录的绝对路径,并同时指定filepath参数中的文件名,在其他用户的目录中创建或重写文件。
CVSS Information
N/A
Vulnerability Type
N/A