漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FileCodeBox 安全漏洞
Vulnerability Description
FileCodeBox是vastsa个人开发者的一个文件快递柜。可以匿名口令分享文件。 FileCodeBox 2.2及之前版本存在安全漏洞,该漏洞源于路径遍历,可能导致任意文件写入。
CVSS Information
N/A
Vulnerability Type
N/A