Typo3 Translations.PHP File...

- AV AC AU C I A
发布: 2003-02-28
修订: 2025-04-13

TYPO3 does not sufficiently sanitize input submitted via URI parameters of potentially malicious data. This issue exists in the 'translations.php' script. By submitting a malicious web request to this script that contains a relative path to a resource and a null character (%00), it is possible to retrieve arbitrary files that are readable by the web server process.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息