Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cacheflow CacheOS WEB管理接口任意缓冲页面代码泄露漏洞
Vulnerability Description
CacheOS是CacheFlow web缓冲系统设计和发行的固件,由CacheFlow维护。 CacheOS存在一个开放8081端口的WEB管理接口,其中存在访问验证漏洞,发送特殊请求可以导致远程用户获得部分缓冲的页面。 当远程用户通过WEB管理接口8081端口进行连接的时候,提交HTTP标准请求给系统,由Cacheserver管理的信息会防止用户访问。但是如果远程用户连接系统并多次发送没有任何HTTP版本类型的请求(如HTTP/1.0或者HTTP/1.1),可导致Cache服务程序泄露部分信息给连接用
CVSS Information
N/A
Vulnerability Type
N/A