Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phPay main.php 本地不完全黑名单漏洞
Vulnerability Description
Windows中phPay 2.02.01版本中的main.php存在不完全黑名单漏洞,远程攻击者可以借助config参数(参数包含一个"..\")引起目录游历攻击并执行任意本地文件。
CVSS Information
N/A
Vulnerability Type
N/A