Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
rssh 命令执行漏洞
Vulnerability Description
rssh是一款使用在Linux中的Shell,它能够为特定用户提供通过scp和sftp登陆某系统的权限。 rssh 2.2.2及之前版本存在绕过安全限制漏洞。 由于没有适当的限制可以运行的程序,远程认证用户可通过rdist -P、rsync或scp -S,绕过安全限制,执行任意程序。
CVSS Information
N/A
Vulnerability Type
N/A