Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence in the login parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SQL-Ledger am.pl 目录遍历漏洞
Vulnerability Description
SQL-Ledger 2.6.27版本的am.pl中存在目录遍历漏洞。它只检查空(%00)字符是否存在以便防止目录遍历攻击,这使得远程攻击者可以借助登录参数中的..,运行任意的可执行文件和绕过身份认证。
CVSS Information
N/A
Vulnerability Type
N/A