关联漏洞
标题:
Pichome 路径遍历漏洞
(CVE-2025-1743)
描述:Pichome是zyx0814个人开发者的一款图片与媒体文件管理功能强大的开源网盘程序。 Pichome 2.1.0版本存在路径遍历漏洞,该漏洞源于文件/index.php?mod=textviewer的参数src会导致路径遍历。
描述
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
文件快照
id: CVE-2025-1743
info:
name: Pichome 2.1.0 - Arbitrary File Read
author: 3th1c_yuk1
severity
...
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。