漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Arbitrary file deletion on logout
Vulnerability Description
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache JSPWiki 访问控制错误漏洞
Vulnerability Description
Apache JSPWiki是美国阿帕奇(Apache)基金会的一款基于Java、Servlet和JSP构建的开源WikiWiki引擎。 Apache JSPWiki 存在访问控制错误漏洞,该漏洞允许远程攻击者删除托管 JSPWiki 实例的系统中的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A