Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Progress Webspeed Messenger _CPYFile.P 未授权访问漏洞
Vulnerability Description
Progress Webspeed Messenger存在多个未授权访问漏洞。远程攻击者可以通过调用提交到(1)cgiip.exe或(2)wsisa.dll的WService参数中的webutil/_cpyfile.p,读取、创建、修改和运行任意文件。
CVSS Information
N/A
Vulnerability Type
N/A