eXtplorer是一套基于PHP的在线文件管理程序,它支持在线浏览文件和文件夹以及作为FTP客户端登录FTP服务器。 eXtplorer 2.1.2、2.1.1和2.1.0版本中的ext_find_user()函数中存在身份验证绕过漏洞。远程攻击者可通过向index.php文件发送action=login请求利用该漏洞绕过认证机制并获取未授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-18023 | ImageMagick 缓冲区错误漏洞 | |
| CVE-2018-18024 | ImageMagick 安全漏洞 | |
| CVE-2018-18025 | ImageMagick 缓冲区错误漏洞 | |
| CVE-2015-9273 | WordPress wp-slimstat插件跨站脚本漏洞 | |
| CVE-2018-18021 | Linux kernel KVM 安全漏洞 |
No comments yet