Page Engine CMS 2.0 Basic和Pro中存在多个目录遍历漏洞。远程攻击者可以借助对: (1)modules/recent_poll_include.php,(2)modules/login_include.php,和(3) modules/statistics_include.php和(4) configuration.inc.php in includes/的fPrefix参数中的目录遍历序列,包含和运行任意本地文件。
Page Engine CMS 2.0 Basic和Pro中存在多个目录遍历漏洞。远程攻击者可以借助对: (1)modules/recent_poll_include.php,(2)modules/login_include.php,和(3) modules/statistics_include.php和(4) configuration.inc.php in includes/的fPrefix参数中的目录遍历序列,包含和运行任意本地文件。