Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX user on the dom0, and then access a potentially reuse an already opened VPS console.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dtc-xen 竞争条件问题漏洞
Vulnerability Description
dtc-xen是一款SOAP守护程序,主要用于对Xen VM进行控制面板管理。 dtc-xen 0.5.4之前的0.5.x版本中存在竞争条件问题漏洞。攻击者可借助特制请求利用该漏洞以xenXX用户身份访问bash,进而使用已经打开的VPS控制台。
CVSS Information
N/A
Vulnerability Type
N/A