漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion
Vulnerability Description
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Cube-Root Directory Serve 路径遍历漏洞
Vulnerability Description
Cube-Root Directory Serve是Cube-Root组织的一款提供目录服务功能的数据库系统。 Cube-Root Directory Serve 1.3.7及之前版本存在路径遍历漏洞,该漏洞源于lib/middleware/file-remove.js中间件未清理req.query.file参数,导致路径遍历,可能允许未经身份验证的远程攻击者删除预期服务目录之外的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A