Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code execution by requesting the .jsp file at a /assets URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dotCMS 安全漏洞
Vulnerability Description
dotCMS是美国dotCMS公司的一套内容管理系统(CMS)。该系统支持RSS订阅、博客、论坛等模块,并具有易于扩展和构建的特点。 dotCMS 4.1.1版本中的com/dotmarketing/servlets/AjaxFileUploadServlet.class文件存在任意文件上传漏洞。远程攻击者借助‘fieldName’参数中的跨站脚本序列利用该漏洞向任意位置上传.jsp文件。
CVSS Information
N/A
Vulnerability Type
N/A