Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0
Vulnerability Description
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
Fortra GoAnywhere 安全漏洞
Vulnerability Description
Fortra GoAnywhere是美国Fortra公司的一种安全的文件传输解决方案。 Fortra GoAnywhere 7.8.0之前版本存在安全漏洞,该漏洞源于错误消息包含绝对服务器路径,可能导致应用映射模糊测试。
CVSS Information
N/A
Vulnerability Type
N/A