ClipBucket v5 在 5.5.3-#197 版本之前,其管理员模板编辑器中存在路径遍历漏洞。攻击者可以通过在“文件夹”参数中提供目录遍历序列,将 PHP 文件覆盖,从而获得对系统的控制。拥有管理模板访问权限的攻击者可以遍历 layout 目录之外的文件,修改可执行的 PHP 文件,并以 Web 服务器用户的身份实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MacWarrior | clipbucket-v5 | < 5.5.3-#197 |
affected |
5.5.3-#197 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MacWarrior | clipbucket-v5 | 0 ~ 5.5.3-#197 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet