Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CVS未文档化标记信息泄露漏洞
Vulnerability Description
Concurrent Versions System (CVS)是一款开放源代码的版本控制软件。 CVS存在未文档化命令参数开关标记,远程攻击者可以利用这个漏洞获得敏感信息。 问题存在于src/history.c文件中的'history'命令的未公开开关,-X命令选项指定历史文件名,允许攻击者判断任意系统文件或目录是否存在,或者CVS进程是否能访问它们。可导致敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A