Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ProjectSend 路径遍历漏洞
Vulnerability Description
ProjectSend(前称cFTP)是一套基于PHP和MySQL的自托管应用程序。 Projectsend存在安全漏洞,攻击者可利用该漏洞可上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A