漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
diyhi bbs File Compression FilePackageManageAction.java information disclosure
Vulnerability Description
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes information disclosure. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
diyhi bbs 安全漏洞
Vulnerability Description
diyhi bbs(巡云轻论坛系统)是diyhi个人开发者的一个论坛系统。 diyhi bbs 6.8及之前版本存在安全漏洞,该漏洞源于对文件src/main/java/cms/web/action/filePackage/FilePackageManageAction.java中参数idGroup的错误操作导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A