Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Winamp Web Interface CControl::Download函数任意类型文件下载漏洞
Vulnerability Description
Winamp Web Interface (Wawi) 7.5.13及更早版本中的CControl::Download函数(/dl URI)远程认证用户可以通过在一个file参数内的文件名尾巴上加"." (点)来下载任意类型文件。和IsWinampFile函数的错误行为有关。
CVSS Information
N/A
Vulnerability Type
N/A