HUBzero CMS(版本 2.2.32 及之前版本)中的项目文件上传处理器存在路径遍历漏洞,允许已认证的项目成员将任意文件写入项目仓库之外的位置。攻击者可以通过在上传参数中注入路径遍历序列,将文件写入攻击者指定的路径,并拥有 Web 服务器权限,从而可能实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hubzero | hubzero-cms | 0 ~ 2.2.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet