Xephyrus Java Simple Template Engine...

- AV AC AU C I A
发布: 2004-08-16
修订: 2025-04-13

Xephyrus Java Simple Template Engine is reported prone to a directory traversal vulnerability due to insufficient sanitization of user-supplied file-token data. Xephyrus Java Simple Template Engine permits that files may be loaded into templates using a 'file-token'. However, 'file-token' values may be overridden by URI parameters that are specified in a request for the script that contains 'file-token' entries.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息