TYPO3是瑞士TYPO3协会维护的一套免费开源的内容管理系统(框架)(CMS/CMF)。restler extension是其中的一个HTTP客户端库扩展。Luracast Restler是其中的一个多格式Web API服务器。 TYPO3中的restler extension 1.7.1之前的版本中的Luracast Restler 3.0.0及之前的版本中的public/examples/resources/getsource.php文件存在目录遍历漏洞。远程攻击者可借助‘file’参数利用该漏洞读
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 is susceptible to local file inclusion in public/examples/resources/getsource.php. This could allow remote attackers to read arbitrary files via the file parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-15363.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-15364 | Ccsv 安全漏洞 | |
| CVE-2017-15360 | Paessler PRTG Network Monitor 跨站脚本漏洞 | |
| CVE-2017-15300 | EWBF Cuda Zcash Miner 安全漏洞 | |
| CVE-2017-15304 | Airtame HDMI dongle 安全漏洞 | |
| CVE-2017-15305 | NexusPHP 跨站脚本漏洞 |
No comments yet