Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netrik Textarea 'form-file.c' 任意命令执行漏洞
Vulnerability Description
Netrik 1.15.4及更早版本中的form-file.c中的edit_textarea函数在编辑字段时未正确验证临时文件名,攻击者可以通过在文件名中的shell元字符来执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A