Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SQL-Ledger/LedgerSMB 目录遍历漏洞
Vulnerability Description
SQL-Ledger和LedgerSMB 1.1.5之前版本中存在目录遍历漏洞。远程攻击者可以借助与用户和用户字符串相邻的.字符,读取和重写任意文件以及执行任意代码。这些字符串会被黑名单函数移除。黑名单函数会过滤掉这些字符串和使..字符串崩溃。
CVSS Information
N/A
Vulnerability Type
N/A