关键信息摘录 CVE编号: CVE-2016-3972 漏洞类型: Directory Traversal 受影响的软件及版本: DotCMS 3.5 Beta (latest version) 漏洞描述: - This vulnerability was found in the 'TailLogServlet' of DotCMS, which could be exploited to access files outside the intended directory structure. 受影响的文件: 漏洞细节: - The has a flaw where the input file path is not properly validated. - Attackers can use directory traversal techniques (e.g., ) to access files outside the designated log directory. POC(概念验证)示例: - 步骤1: 登录系统 - 步骤2: 访问以下URL: - 利用结果: Unauthorized access to system log files can be achieved, which may include sensitive information.