Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation leads to read access, and write access (depending on file permissions), to the symlink target. Third, the attacker can import a Git repository that contains a symlink, similarly leading to read and write access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
b3log Wide 注入漏洞
Vulnerability Description
b3log Wide是一套基于Web的Go语言集成开发环境(IDE)。 b3log Wide 1.6.0之前版本中存在安全漏洞。攻击者可利用该漏洞访问任意文件。
CVSS Information
N/A
Vulnerability Type
N/A