漏洞标题
sjqzhang go-fastdfs 文件上传 uploa 上传路径遍历
漏洞描述信息
sjqzhang go-fastdfs 文件上传漏洞,可实现上传路径遍历
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
sjqzhang go-fastdfs File Upload uploa upload path traversal
漏洞描述信息
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224768.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
路径遍历:’../filedir’
漏洞标题
go-fastdfs 代码问题漏洞
漏洞描述信息
go-fastdfs是一个简单的分布式文件系统(私有云存储),具有无中心、高性能,高可靠,免维护等优点,支持断点续传,分块上传,小文件合并,自动同步,自动修复。 sjqzhang go-fastdfs 1.4.3版本及之前版本存在安全漏洞。攻击者利用该漏洞可以访问存储在web根文件夹之外的文件和目录。
CVSS信息
N/A
漏洞类别
代码问题