Volmarg 个人管理系统中存在一个路径遍历漏洞,允许已认证的 attackers 通过向 端点提供绝对文件系统路径来读取任意文件。该路由的路径参数在未对允许的基目录进行规范化处理的情况下,直接传递给 ,使得攻击者能够获取 PHP-FPM 工作进程可访问的敏感文件,且无需使用目录遍历序列(如 )。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Volmarg | personal-management-system | 0 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet