Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because credentials are present in that config.php file).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CMS ISWEB 路径遍历漏洞
Vulnerability Description
CMS ISWEB是一套内容管理系统(CMS)。 CMS ISWEB 3.5.3版本中存在目录遍历漏洞。攻击者可利用该漏洞下载config.php文件,控制应用程序。
CVSS Information
N/A
Vulnerability Type
N/A