Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Photostand敏感信息泄露漏洞
Vulnerability Description
Photostand 1.2.0版本允许远程攻击者通过(1)PHPSESSID cookie或(2)index.php中文章操作id参数中的'字符,在不同的错误信息中显示路径,获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A