漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Horde IMP < 7.0.1 Path Traversal via Compose.php img src
Vulnerability Description
Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; unauthenticated exploitation is also achievable via CSRF against an active authenticated session.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Horde imp 路径遍历漏洞
Vulnerability Description
Horde imp是Horde组织开源的一个基于 web 的网络邮件系统。 Horde imp 7.0.1之前版本存在路径遍历漏洞,该漏洞源于lib/Compose.php存在路径遍历问题,允许经过身份验证的攻击者通过在img src URL的CKEditor路径前缀后嵌入遍历序列来读取服务器文件系统中的任意文件。攻击者可绕过stripos()前缀验证,导致file_get_contents()读取敏感文件并作为MIME部分渗漏到外发邮件中;未经身份验证的攻击也可通过对活动的已验证会话进行CSRF来实现。
CVSS Information
N/A
Vulnerability Type
N/A