Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ocPortal 路径遍历漏洞
Vulnerability Description
ocPortal中存在目录遍历漏洞,该漏洞源于传到site/catalogue_file.php(当"original_filename"已创建好时)中的“file”参数中的输入在被使用至显示文件之前未经正确认证。攻击者可利用该漏洞借助目录遍历序列泄露任意文件的内容。ocPortal 7.1.5版本中存在漏洞,之前版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A