Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KnowledgeTree Open Source view.php 信息泄露漏洞
Vulnerability Description
KnowledgeTree Open Source 中的view.php允许远程攻击者通过特制fDocumentId参数(在结果的出错信息内显示路径)来获取完整的安装路径名。注意:此问题可能是由另一个漏洞引起,因此此向量也产生XSS。
CVSS Information
N/A
Vulnerability Type
N/A