Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
X2Engine X2CRM ‘file’参数本地文件包含漏洞
Vulnerability Description
X2Engine X2CRM是美国X2Engine公司的一套开源的客户关系管理系统(CRM)。该系统提供生成销售报价、制定销售流程和快速查看联系人等功能。 X2Engine X2CRM 3.4.1及之前的版本中存在目录遍历漏洞,该漏洞源于index.php/admin/translationManager脚本没有正确过滤用户提交的输入。远程攻击者可通过向‘file’参数提交‘..’利用该漏洞包含并执行任意本地文件。
CVSS Information
N/A
Vulnerability Type
N/A