Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cagintranet Networks GetSimple CMS 信息泄露漏洞
Vulnerability Description
Cagintranet Networks GetSimple CMS是美国Cagintranet Networks公司的一套基于XML的内容管理系统(CMS)。该系统包含主题选择器和编辑器、组件编辑器、图像和文件管理器等。 Cagintranet Networks GetSimple CMS 3.1.1版本至3.3.5 Beta 1之前3.3.x版本的admin/api.php脚本中存在XML外部实体漏洞。在特定的配置中,远程攻击者可借助‘data’参数利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A