Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in BitKinex 2.9.3 allow remote FTP and WebDAV servers to create or overwrite arbitrary files via a .. (dot dot) in (1) a response to a LIST command from the BitKinex FTP client and (2) a response to a PROPFIND command from the BitKinex WebDAV client. NOTE: this can be leveraged for code execution by writing to a Startup folder.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Barad_dur Bitkinex 多个目录遍历漏洞
Vulnerability Description
BitKinex 2.9.3版本存在多个目录遍历漏洞。远程FTP和WebDAV服务商可以借助(1)对LIST指令(来自BitKinex FTP客户端)的响应和(2)对PROPFIND指令(来自BitKinex WebDAV客户端)的响应中的"..",创建或重写任意文件。
CVSS Information
N/A
Vulnerability Type
N/A