Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.%00.../ attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress WP Rocket插件安全漏洞
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。WP Rocket plugin是其中的一个缓存优化插件。 WordPress WP Rocket插件2.9.3版本中存在安全漏洞。远程攻击者可借助0x00字节利用该漏洞绕过安全限制。
CVSS Information
N/A
Vulnerability Type
N/A