cockpit-project Cockpit是cockpit-project团队开源的一款交互式服务器管理界面。 cockpit-project cockpit 364版本之前版本存在路径遍历漏洞,该漏洞源于路径遍历和本地文件包含问题,导致未经身份验证的攻击者可以读取任意文件或通过包含未验证的PATH_INFO执行PHP文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cockpit-hq | cockpit | ≤ 2.14.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cockpit-hq | cockpit | 0 ~ 2.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion (LFI) vulnerability when executed under PHP's built-in CLI server (PHP_SAPI == 'cli-server') or non-normalizing reverse proxies. The application fails to sanitize dot-dot sequences in PATH_INFO routes starting with '/:' and containing '/storage/'. Unauthenticated remote attackers can traverse outside the designated directory to read arbitrary system files. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-58467.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet