Description CVE-2018-13379是SSL VPN中的一个目录遍历漏洞,该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素,导致攻击者可利用该漏洞访问受限目录之外的文件。
Related VulnerabilitiesPoCwp-ssl-insecure-content-fixer-fpd: WordPress Plugin SSL Insecure Content Fixer - Full Path DisclosureH3C SSL VPN 安全漏洞AllinSSL存在默认口令CVE-2019-11510: Pulse Connect Secure SSL VPN Arbitrary File ReadGrafana /avatar 服务器端请求伪造漏洞(CVE-2020-13379)PoCCVE-2014-0160: OpenSSL Heartbleed VulnerabilityPoCCVE-2022-42475: Fortinet SSL-VPN - Heap-Based Buffer OverflowPoCCVE-2017-14186: FortiGate FortiOS SSL VPN Web Portal - Cross-Site ScriptingPoCCVE-2018-13379: Fortinet FortiOS - Credentials DisclosurePoCCVE-2020-13379: Grafana 3.0.1-7.0.1 - Server-Side Request Forgery