Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ClanSphere 2011.3 Local File Inclusion via cs_lang Cookie
Vulnerability Description
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The vulnerability is further exacerbated by null byte injection (%00) to bypass file extension checks.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
ClanSphere 安全漏洞
Vulnerability Description
ClanSphere是ClanSphere组织的一个网站内容管理系统。 ClanSphere 2011.3版本存在安全漏洞,该漏洞源于未正确处理cs_lang cookie参数,可能导致本地文件包含。
CVSS Information
N/A
Vulnerability Type
N/A