Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_sel parameter to (1) updater.php and (2) thumber.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GF-3XPLORER 路径遍历漏洞
Vulnerability Description
GF-3XPLORER是一个基于PHP的文件管理脚本,它提供创建和删除文件和文件夹、文件上传、文件编辑等功能。 GF-3XPLORER 2.4版本中存在路径遍历漏洞,该漏洞源于updater.php和thumber.php脚本没有充分过滤‘lang_sel’参数。远程攻击者可借助目录遍历字符‘..’利用该漏洞包含并执行任意本地文件。
CVSS Information
N/A
Vulnerability Type
N/A