Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Wonko NotFTP config.php本地文件包含漏洞
Vulnerability Description
NotFTP是用PHP编写的基于Web的HTTP-FTP网关。 NotFTP的config.php脚本没有正确地过滤用户所提交的参数,如果远程攻击者在提交的URL请求中使用newlang参数指定了本地系统的恶意文件的话,就可能在Web服务器上读取敏感信息或执行任意代码。以下是config.php脚本中的有漏洞代码段: if (isset($newlang)) { require_once("lib/lang/".$languages[$newlang]["file"]); } elseif (isset(
CVSS Information
N/A
Vulnerability Type
N/A