Rubedo是一套内容管理系统。theme是其中的一个主题组件。 Rubedo 3.4.0及之前版本中的theme组件存在路径遍历漏洞。攻击者可利用该漏洞读取并执行该服务根目录之外的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Rubedo CMS through 3.4.0 contains a directory traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16836.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-16807 | Bro Kerberos protocol解析器安全漏洞 | |
| CVE-2018-16831 | New Digital Group Smarty 安全漏洞 | |
| CVE-2018-16832 | xunfeng anti-csrf decorator 跨站请求伪造漏洞 | |
| CVE-2018-15898 | Subsonic Music Streamer for Android 安全漏洞 |
No comments yet