Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AjaXplorer 目录遍历漏洞
Vulnerability Description
AjaXplorer是一款基于Web的远程文件管理器。该管理器支持上传和下载文件、在线文件编辑、图片预览等。 AjaXplorer 5.0.2及之前的版本中存在目录遍历漏洞,该漏洞源于index.php脚本没有正确过滤download或get_content操作中的‘file’参数。远程经过授权的攻击者可借助目录遍历序列(‘../%00’)利用该漏洞读取任意文件,或通过upload操作中的‘dir’参数上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A