Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the name parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SearchBlox ‘name’参数任意文件覆盖漏洞
Vulnerability Description
SearchBlox是美国SearchBlox公司的一套开源免费的基于Lucene(全文检索引擎工具包)构建的企业搜索和分析解决方案。该方案提供一个基于Web的管理界面,可以管理整个搜索系统。 SearchBlox 7.5及之前的版本中的servlet/CreateTemplateServlet目录中存在目录遍历漏洞。远程攻击者可通过name参数中的‘..’利用该漏洞覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A