Froxlor是Froxlor团队的一套轻量级服务器管理软件。 Froxlor 2.3.6之前版本存在后置链接漏洞,该漏洞源于DataDump.add()在构建导出目标路径时未传递$fixed_homedir参数,绕过符号链接验证,导致客户可以获取系统上任意目录的所有权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41228 | 10.0 CRITICAL | Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that l |
| CVE-2026-41229 | 9.1 CRITICAL | Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generatio |
| CVE-2026-41230 | 8.5 HIGH | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones:: |
| CVE-2026-41233 | 5.4 MEDIUM | Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.ad |
| CVE-2026-41232 | 5.0 MEDIUM | Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allow |
No comments yet