Fred Stuurman SyndeoCMS存在多个目录遍历漏洞。远程验证用户可以借助对starnet/editors/fckeditor/studenteditor.php;starnet/modules/sn_news/edit_content.php, reached through starnet/index.php;和starnet/modules/sn_newsletter/edit_content.php, reached through starnet/index.php的模板参数中的一个.. ,读取任意文件。
Fred Stuurman SyndeoCMS存在多个目录遍历漏洞。远程验证用户可以借助对starnet/editors/fckeditor/studenteditor.php;starnet/modules/sn_news/edit_content.php, reached through starnet/index.php;和starnet/modules/sn_newsletter/edit_content.php, reached through starnet/index.php的模板参数中的一个.. ,读取任意文件。