Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in the f parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
u5CMS 目录遍历漏洞
Vulnerability Description
u5CMS是一套基于PHP、MySQL和Apache的且用于中型网站、会议、审核流程、PayPal支付和在线调查的内容管理系统(CMS)。该系统支持所见即所得编辑器、创建调查表单和数据存储等。 u5CMS 3.9.4之前版本的u5admin/deletefile.php脚本中存在目录遍历漏洞。远程攻击者可借助‘f’参数中的目录遍历字符‘..’或完整路径名利用该漏洞写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A