Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (2) includes/init.php, (3) certain files in includes/cron/, and (4) jpgraph.php, (5) jpgraph_bar.php, (6) jpgraph_pie.php, and (7) jpgraph_pie3d.php in includes/graph/, which leaks the path in error messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Headstart Solutions DeskPRO多个目录遍历漏洞
Vulnerability Description
Headstart Solutions DeskPRO允许远程攻击者可以借助提交对(1)email/mail.php,(2)includes/init.php,(3)includes/cron/中的某个文件和(4)jpgraph.php,(5)jpgraph_bar.php,(6)jpgraph_pie.php, 以及(7)includes/graph/中的jpgraph_pie3d.php的直接请求,获得完整路径。该漏洞在错误信息中泄漏路径信息。
CVSS Information
N/A
Vulnerability Type
N/A