脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
N/A
脆弱性説明
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
CVSS情報
N/A
脆弱性タイプ
N/A
脆弱性タイトル
Drupal 安全漏洞
脆弱性説明
Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Drupal 7.5之前的7.x版本中存在安全漏洞。攻击者可利用该漏洞下载评论附带的文件。
CVSS情報
N/A
脆弱性タイプ
N/A