Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XLoadImage压缩图像命令执行漏洞
Vulnerability Description
远程攻击者可以借助xloadimage 4.1-r2之前版本和xli 1.17之前版本,通过压缩图像文件名中的shell元字符执行任意命令,而这些元字符在调用gunzip指令时没有正确引用。
CVSS Information
N/A
Vulnerability Type
N/A