CWE-427 对搜索路径元素未加控制 类弱点 556 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-427 属于路径遍历类漏洞,指程序在搜索资源时,其路径中包含可由攻击者控制的目录。攻击者通常通过在该目录下放置恶意文件或库,诱导程序加载并执行,从而劫持系统控制权。开发者应避免使用相对路径或不可信的环境变量,转而采用绝对路径,并严格限制相关目录的写入权限,以确保资源加载的安全性。
... System.Runtime.getRuntime().exec("make"); ...func ExecuteGitCommand(name string, arg []string) error { c := exec.Command(name, arg...) var err error c.Path, err = exec.LookPath(name) if err != nil { return err } }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2017-5175 | Advantech WebAccess 安全漏洞 — Advantech WebAccess Versions 8.1 and prior. | 7.8 | - | 2018-05-09 |
| CVE-2017-14010 | iniNet SpiderControl MicroBrowser 安全漏洞 — MicroBrowser | 7.8 | - | 2018-04-26 |
| CVE-2018-5457 | Vyaire Medical CareFusion Upgrade Utility 安全漏洞 — Vyaire Medical CareFusion Upgrade Utility Vulnerability | 7.0 | - | 2018-02-06 |
| CVE-2017-5170 | Moxa SoftNVR-IA Live Viewer 安全漏洞 — Moxa SoftNVR-IA Live Viewer | 7.2 | - | 2018-01-18 |
| CVE-2017-12313 | Cisco Network Academy Packet Tracer software 安全漏洞 — Cisco Network Academy Packet Tracer | 6.7 | - | 2017-11-16 |
| CVE-2017-12314 | Cisco FindIT Network Discovery Utility 安全漏洞 — Cisco FindIT Discovery Utility | 7.8 | - | 2017-11-16 |
| CVE-2017-14020 | 多款AutomationDirect产品安全漏洞 — CLICK Programming Software (Part Number C0-PGMSW) | 7.8 | - | 2017-11-13 |
| CVE-2017-14029 | Trihedral VTScada 安全漏洞 — Trihedral Engineering Limited VTScada | 7.8 | - | 2017-11-06 |
| CVE-2017-14017 | Progea Movicon 安全漏洞 — Progea Movicon SCADA/HMI | 7.8 | - | 2017-10-19 |
| CVE-2017-5147 | AzeoTech DAQFactory 安全漏洞 — AzeoTech DAQFactory | 8.4 | - | 2017-09-09 |
| CVE-2017-11158 | Synology Cloud Station Drive for Windows 安装程序漏洞 — Cloud Station Drive | 7.8 | - | 2017-08-31 |
| CVE-2017-12717 | Advantech WebAccess 安全漏洞 — Advantech WebAccess | 7.8 | - | 2017-08-30 |
| CVE-2017-11159 | Synology Photo Station Uploader for Windows 安全漏洞 — Photo Station Uploader | 7.8 | - | 2017-08-23 |
| CVE-2017-5176 | Rockwell Automation Connected Components Workbench 安全漏洞 — Rockwell Automation Connected Components Workbench | 7.0 | - | 2017-05-19 |
| CVE-2017-6051 | BLF-Tech LLC VisualView HMI 安全漏洞 — BLF-Tech LLC VisualView HMI | 7.8 | - | 2017-05-08 |
| CVE-2017-6033 | Schneider Electric Interactive Graphical SCADA System Software 安全漏洞 — Schneider Electric Interactive Graphical SCADA System Software | 7.8 | - | 2017-04-07 |
CWE-427(对搜索路径元素未加控制) 是常见的弱点类别,本平台收录该类弱点关联的 556 条 CVE 漏洞。