Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Takes 安全漏洞
Vulnerability Description
Takes是Yegor Bugayenko个人开发者的一个面向对象Java Web开发框架。 Takes 2.0-SNAPSHOT及之前版本存在安全漏洞,该漏洞源于未规范化HTTP请求路径,可能导致任意文件读取。
CVSS Information
N/A
Vulnerability Type
N/A