KodExplorer 4.55 之前的版本在 app/function/helper.function.php 文件的 unzip_pre_name() 函数中存在路径穿越漏洞。该漏洞中,单次非递归的 str_replace() 净化逻辑可被构造的特殊文件名(如 “....//”)绕过;同时,KodArchive.class.php 中调用 PclZip 的 extract() 函数时未启用 PCLZIP_OPT_EXTRACT_DIR_RESTRICTION 选项,进一步加剧了安全风险。经过身份验证的攻击者可以
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kalcaddle | KodExplorer | < 4.55 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kalcaddle | KodExplorer | 0 ~ 4.55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet