漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.
漏洞信息
N/A
漏洞
N/A
漏洞
Zomplog 'upload_files.php' 未授权访问漏洞
漏洞信息
Zomplog 3.8.1版本及其早期版本存储潜在敏感信息有不充分访问控制的web源使远程攻击者下载用户上载的文件,例如借助/upload的一个直接请求获得的一个目录列表检索档案文件。
漏洞信息
N/A
漏洞
N/A