Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nortel SSL VPN跨站脚本/命令执行漏洞
Vulnerability Description
Nortel SSL VPN是远程访问安全解决方案,可以使用安全套接字层(SSL)做为基础安全协议。 Nortel的SSL VPN的WEB界面没有充分的验证用户输入,因此攻击者可以在某些页面的链接中隐藏命令。由于从这些页面中所调用的Java Applet是经过加密签名的,因此可能以使用浏览器用户的权限执行任意系统命令。
CVSS Information
N/A
Vulnerability Type
N/A