xboy (topsec)

1 exploit Active since Aug 2022
CVE-2022-36261 WRITEUP CRITICAL WRITEUP
taocms 3.0.2 - Arbitrary File Deletion via Admin File Deletion Endpoint
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt
CVSS 9.1