CVE-2018-19181

CVE-2018-19181

statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.

Source: CVE-2018-19181

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다