Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-50449: JFinalCMS存在未授权目录遍历漏洞 · Issue #I7WGC6 · 樱木/JFinalCMS - Gitee.com

JFinalCMS 5.0.0 could allow a remote attacker to read files via …/ Directory Traversal in the /common/down/file fileKey parameter.

CVE
#windows#linux#git

在/common/down/file路由功能下,可以对参数fileKey设计带有恶意性质内容的文件名实现目录穿越,从而下载已知目录内的任意已知文件名,且该行为并不需要进行登录。

poc:
Linux:   /../../../../../../../etc/passwd
Windows:  /../../../../../../../test.txt (test.txt为测试用的在根目录下的文件)

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907