在 2.2.5 版本之前的 Froxlor 中,系统未对子域名重定向 URL 中的换行字符进行校验。这使得经过身份验证的客户能够注入任意的 Nginx 或 Apache 配置指令。攻击者可以提交包含字面换行符的 URL,这些换行符会在 cron 重建过程中被原样写入 vhost 配置文件,从而导致 Web 服务器配置损坏、服务中断,甚至导致托管域名的 HTTP 响应被劫持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58383 | 7.3 HIGH | Froxlor before 2.2.0 Insecure File Permissions mysql.conf |
| CVE-2026-90935 | 4.3 MEDIUM | Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API |
| CVE-2026-90936 | 4.3 MEDIUM | Froxlor before 2.3.7 Information Disclosure via customer_email.php |
No comments yet