Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Proxytunnel 远程格式串任意指令执行漏洞
Vulnerability Description
ProxyTunnel是一款可通过HTTPS代理的软件。 ProxyTunnel在记录非法代理回答时存在格式串问题,远程服务器控制者可以利用这个漏洞以进程权限在系统上执行任意指令。 Gentoo报告当ProxyTunnel运行在守护进程模式下,由于在记录非法代理应答处理中存在格式串问题,远程恶意服务器可以通过构建特殊的非法应答,返回Proxytunnel主机值来触发此漏洞,进行构建提交数据可能以进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A