Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ActivePost Standard多个安全漏洞
Vulnerability Description
ActivePost Standard是一款用于公司内交流的程序,可发消息,聊天,文件传送等。 ActivePost Standard存在多个问题,远程攻击者可以利用这些漏洞对服务进行拒绝服务,破坏系统文件,获得密码信息等攻击。 1. 文件服务器崩溃: 文件服务器监听6004端口,可上传下载文件,攻击者发送包含超过4074字符的文件名的文件,就会导致服务程序崩溃。 2. 文件服务器目录遍历: 如果文件名包含多个'../'字符,可导致覆盖已经存在的文件,攻击者可以通过此漏洞在任意系统位置建立文件或覆盖文件。
CVSS Information
N/A
Vulnerability Type
N/A