Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie files via (1) DNS spoofing, (2) a URL on the command line, or (3) a URL in the configuration file. NOTE: the same attack vectors apply to common web browsers that are able to communicate with untrusted web servers, and other problems related to DNS design issues. Therefore this may not be a specific vulnerability. However, a client would reasonably expect to receive content only from the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Electric Sheep一致性检查漏洞
Vulnerability Description
Electric Sheep 2.6.3没有要求从服务器到客户端的认证或者一致性检查,因此远程攻击者可以通过(1)DNS 欺骗,(2)命令行中的URL或(3)配置文件中的URL来下载任意MPEG影片。
CVSS Information
N/A
Vulnerability Type
N/A