Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Business Objects WebIntelligence访问控制绕过文件删除漏洞
Vulnerability Description
Business Objects WebIntelligence 2.7.0版本到2.7.4版本只加强客户端的访问控制,远程认证用户可以借助制作的使用InfoView web客户端的删除请求在服务器上删除任意文件。
CVSS Information
N/A
Vulnerability Type
N/A