Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Webtrees 安全漏洞
Vulnerability Description
Webtrees是一个 Web 应用程序,用于在线发布家谱、与家庭成员协作等。 Webtrees 2.1.18版本存在安全漏洞,该漏洞源于攻击者通过media_folder参数可以导航到其他目录,以访问应用程序文件系统中的敏感文件。
CVSS Information
N/A
Vulnerability Type
N/A