脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
eXtplorer exposes /usr and /etc/extplorer over HTTP
脆弱性説明
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
脆弱性タイプ
信息暴露
脆弱性タイトル
eXtplorer 信息泄露漏洞
脆弱性説明
eXtplorer是一款基于PHP的文件管理器。 eXtplorer中的debian/patches/debian-changes-2.1.0b6+dfsg-1或debian/patches/adds-a-makefile.patch补丁文件存在信息泄露漏洞。攻击者可利用该漏洞访问/usr/和/etc/extplorer/系统路径,获取信息/数据并可能在Web服务器上执行代码。
CVSS情報
N/A
脆弱性タイプ
N/A