SecLists.Org | Full Disclosure 中文 关注 Flextype v1.0.0-alpha.3 入口复制路径遍历漏洞允许任意目录复制和文件披露 发帖人:Ron E,发布于 9 月 3 日 描述 Flextype CMS v1.0.0-alpha.3 在条目复制功能中存在路径遍历漏洞。经过身份验证的远程攻击者可以在提交至 /api/v1/entries/copy 的 source_id 和 destination_new_id 参数中提供目录遍历序列。 Flextype 通过直接将提供的条目标识符与配置的条目目录拼接来构建条目目录路径,而未能充分…… Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure seclists.org SecLists.Org | Full Disclosure 中文 RSS thenote.app
/api/v1/entries/copy的source_id和destination_new_id参数中提供目录遍历序列。 Flextype 通过直接将提供的条目标识符与配置的条目目录拼接来构建条目目录路径,而未能充分……