Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HTTP File Server 多个目录遍历漏洞
Vulnerability Description
HTTP File Server是一款专为个人用户所设计的HTTP文件服务器,它提供虚拟档案系统,支持新增、移除虚拟档案资料夹等。 HFS使用用户名做为日志文件的文件名时,允许远程攻击者通过一个带有..的账号名创建任意文件和目录,并且使用/ URI中包含"/?%0a"时可以通过带有..的账号名向任意文件追加数据。
CVSS Information
N/A
Vulnerability Type
N/A