Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gast Arbeiter文件上传验证漏洞
Vulnerability Description
Gast Arbeiter是一款由perl编写的实时消息聊天工具。 Gast Arbeiter在处理文件上传时缺少充分的过滤,远程攻击者可以利用这个漏洞写任意文件到系统导致权限提升。 Gast Arbeiter提供CGI接口可上传独立的文件,由于对用户提交的数据缺少充分过滤,可利用目录遍历把文件写到系统任意位置。可导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A