Dozzle 在 11.1.2 之前的版本中,在通过日志下载端点构建 ZIP 归档条目名称时,未能对容器显示名称进行安全过滤。攻击者若能对容器进行标签命名,便可以利用路径遍历序列,在用户下载并解压日志时,将文件写入解压目录之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet