PHP-Nuke mailattach.php Remote File...

- AV AC AU C I A
发布: 2003-10-04
修订: 2025-04-13

The PHP-Nuke mailattach.php script does not properly filter input, potentially allowing files to be uploaded to the system outside the webroot. By including directory traversal characters with the filename to upload, an attacker could possibly overwrite other files on the system or save malicious files to sensitive locations.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息