Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bitweaver ‘rankings.php’ 本地文件包含漏洞
Vulnerability Description
Bitweaver是一套免费、开源的Web应用框架和内容管理系统。该系统包含文章管理、Wiki、Blog、图片管理、日历、用户管理等模块。 Bitweaver中存在本地文件包含漏洞,该漏洞源于对用户提供的输入未经充分过滤。攻击者可利用此漏洞在web服务器进程中查看文件,进而执行本地脚本,这可能导致进一步的攻击。Bitweaver 2.8.1版本中存在漏洞,其它版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A