Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenX 目录遍历漏洞
Vulnerability Description
OpenX(前称phpAdsNew)是美国OpenX公司的一套开源的广告管理与跟踪系统。该系统提供一个横幅广告管理界面,支持电子邮件通知客户广告统计信息的功能。 OpenX 2.8.10及之前的版本中存在目录遍历漏洞,该漏洞源于plugin-preferences.php和plugin-settings.php脚本没有充分过滤‘group’参数。远程攻击者可利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A