Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://forum.terra-master.com/cn/viewtopic.php?f=100&t=3842&p=17623#p17623 | not applicable |
https://forum.terra-master.com/cn/viewtopic.php?f=100&t=3842&p=17623#p | not applicable |