Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zomplog 'upload_files.php' 未授权访问漏洞
Vulnerability Description
Zomplog 3.8.1版本及其早期版本存储潜在敏感信息有不充分访问控制的web源使远程攻击者下载用户上载的文件,例如借助/upload的一个直接请求获得的一个目录列表检索档案文件。
CVSS Information
N/A
Vulnerability Type
N/A