Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ELinks URL串处理smbclient远程命令注入漏洞
Vulnerability Description
ELinks是一款Linux系统下的开源纯文本浏览器。 ELinks在处理SMB相关的URL串时存在命令注入漏洞,远程攻击者可能利用此漏洞在用户机器上执行任意命令。ELinks没有正确验证"smb://"URL串就调用smbclient命令,允许攻击者在上述URL中注入smbclient命令下载和覆盖本地文件或向SMB共享上传文件。
CVSS Information
N/A
Vulnerability Type
N/A