Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arbitrary file deletion on logout
Vulnerability Description
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache JSPWiki 访问控制错误漏洞
Vulnerability Description
Apache JSPWiki是美国阿帕奇(Apache)基金会的一款基于Java、Servlet和JSP构建的开源WikiWiki引擎。 Apache JSPWiki 存在访问控制错误漏洞,该漏洞允许远程攻击者删除托管 JSPWiki 实例的系统中的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A