Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
cPanel 安全漏洞
Vulnerability Description
cPanel是美国cPanel公司的一套基于Web的自动化主机托管平台。该平台主要用于自动化管理网站和服务器。 cPanel存在安全漏洞,该漏洞源于权限管理不当和路径过滤不足,可能导致通过cpdavd附件下载端点读取服务器任意文件。
CVSS Information
N/A
Vulnerability Type
N/A