phpMyFAQ Action Parameter Arbitrary...

- AV AC AU C I A
发布: 2004-05-18
修订: 2025-04-13

phpMyFAQ is prone to an arbitrary file disclosure vulnerability that can allow a remote attacker to gain access to potentially sensitive information. This vulnerability exists due to insufficient sanitization of user-supplied data via the 'action' parameter. An attacker can disclose files by passing a relative path to a file and concatenating the path with a '\0' string terminator. phpMyFAQ version 1.3.12 is prone to this issue.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息