Rubedo 存在任意文件读取漏洞 (CVE-2018-16836)

2021-11-08 Rubedo PoC No

Description

Rubedo3.4.0在theme组件中包含一个目录遍历漏洞,允许未经身份验证的攻击者读取和执行服务根路径之外的任意文件,如/theme/default/img/%2e%2e/.//etc/passwdURI所示。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities