疑似Oday
Detected publicly accessible KCFinder instances that may have allowed arbitrary file uploads and remote code execution (RCE).Exposure of KCFinder could have allowed an attacker to gain unauthorized access to the file manager and upload malicious files.
id: kcfinder-exposure
info:
name: KCFinder - Exposure
author: theamanrawat
severity: high
d
...