Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Advanced Guestbook Lang Cookie Parameter 路径遍历和安全跳过漏洞
Vulnerability Description
Advanced Guestbook 中存在目录遍历漏洞。远程攻击者可以借助一个超长的cookie中的..,绕过.htaccess设置,运行任意的PHP本地文件或读取本地模板。该cookie被没有.php扩展名的文件名所跟随。
CVSS Information
N/A
Vulnerability Type
N/A