onefilecms.php in OneFileCMS attraverso 2017/10/08 potrebbe consentire agli aggressori di leggere file arbitrari tramite i e f parametri, come dimostrato da? i = etc / passwd & f = & p = raw_view per il file / etc / passwd. |
https://github.com/Self-Evident/OneFileCMS/issues/50 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13123 |
Vulnerabilità: CVE-2018-13123
