漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
Vulnerability Description
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Agile Logix Store Locator WordPress 路径遍历漏洞
Vulnerability Description
Agile Logix Store Locator WordPress是Agile Logix公司的一款WordPress店铺定位插件。 Agile Logix Store Locator WordPress 1.6.9之前版本存在路径遍历漏洞,该漏洞源于在将参数用于文件路径前未进行验证,导致管理员等高权限用户可读取服务器上任意.php 文件,包括含有数据库凭证和认证密钥的配置文件。
CVSS Information
N/A
Vulnerability Type
N/A