Discuz! 路径信息泄露漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

目录\uc_client\data\cache\,\forumdata\cache等下面的文件里对如:<br /> <br /> $_CACHE['settings'] = array (<br /> 'accessemail' => '',<br /> 'censoremail' => '',<br /> 'censorusername' => '',<br /> 'dateformat' => 'y-n-j',<br /> 'doublee' => '1',<br /> 'nextnotetime' => '0',<br /> 'timeoffset' => '28800',<br /> );<br /> <br /> <br /> $_DCACHE['settings'] = array (<br /> 'accessemail' => '',<br /> 'adminipaccess' => '',<br /> 'admode' => '1',<br /> 'archiverstatus' => '1',<br /> 'attachbanperiods' => '',<br /> 'attachimgpost' => '1',<br /> <br /> 数组$_DCACHE,$_CACHE等没有初始化,其实dz的安全人员已经考虑到了这个问题,如在include\common.inc.php <br /> <br /> $_DCOOKIE = $_DSESSION = $_DCACHE = $_DPLUGIN = $advlist = array();<br /> <br /> 但是想对于独立的Discuz! cache file并没有初始化,当我们提交?_CACHE=1 或者_DCACHE=2 导致错误而暴露路径等信息. Discuz 6 等待官方补丁.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息