Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal IMCE模块删除任意文件漏洞
Vulnerability Description
Drupal是很著名的开源CMS,仿照了blog程序模式,但比普通的blog更灵活,可以做各种网站的内容管理平台。 Drupal的IMCE模块实现上存在输入验证漏洞,远程攻击者可能利用此漏洞删除服务器上的任意文件。 IMCE在调用删除功能时没有正确验证文件的相对路径,具有删除文件权限的用户可以利用输入恶意路径删除服务器上的任意文件。 <*>
CVSS Information
N/A
Vulnerability Type
N/A