Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Piwigo 安全漏洞
Vulnerability Description
Piwigo是Piwigo团队的一套基于Web的相册软件。该软件支持照片发布、管理、多种浏览方式(类别、标签、时间)等。Batch Manager component是其中的一个管理器组件。 Piwigo 2.8.3及之前的版本中的admin/plugin.php文件存在安全漏洞,该漏洞源于程序没有验证‘section’变量。攻击者可利用该漏洞造成信息泄露,并执行代码。
CVSS Information
N/A
Vulnerability Type
N/A