WordPress 的 Super Forms – Drag & Drop Form Builder 插件在 6.3.316 及更早的所有版本中存在目录遍历漏洞,该漏洞可通过 函数触发。这使得未经身份验证的攻击者能够读取服务器上的任意文件内容,其中可能包含敏感信息。 可选设置 默认值为空,即默认配置下无需身份验证即可利用;启用此设置可防止未经身份验证的攻击者利用该漏洞,但并不能从根本上修复目录遍历漏洞本身。 在 Linux 系统上,要成功利用该漏洞,必须存在一个真实的 13 位时间戳目录;而在 Windows 系统
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder | ≤ 6.3.316 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebRehab | Super Forms – Drag & Drop Form Builder | 0 ~ 6.3.316 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet