PHProjekt Directory Escaping Vulnerability...

- AV AC AU C I A
发布: 2001-05-08
修订: 2025-04-13

PHProjekt is a freely available, open source PHP Groupware package. It is actively maintained by the PHProjekt Development Team. A problem in the package could allow users of the software access to unauthorized resources. Due to insufficient checking of input, it is possible for a user to append a request with the dot-dot (..) extension, breaking out of the confines of the configuration limitations. This makes it possible for remote user to gain access to restricted resources, and gather information or potentially gain local access.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息