new4시간 전· 1 sources

WordPress: 인증 없이 악용 가능한 경로 순회 취약점, 조건 충족 시 원격 코드 실행으로 이어짐

Why it matters

<ul> <li>WordPress의 <strong><code>get_page_template()</code></strong> 에서 인증 없는 공격자가 활성 테마 디렉터리 밖의 읽기 가능한 로컬 <code>.php</code> 파일을 포함시킬 수 있는 취약점이 발견됨</li> <li><strong>원격 코드 실행(RCE)</strong> 으로 이어지려면 활성...

1
Sources
+1
24h
Growth
1d
Active

Sources

Related Issues