Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Snort Report nmap.php/nbtscan.php RCE
Vulnerability Description
Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result in full compromise of the underlying system.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Snort Report 安全漏洞
Vulnerability Description
Snort Report是Snort团队的一个检测报告管理系统。 Snort Report 1.3.2之前版本存在安全漏洞,该漏洞源于nmap.php和nbtscan.php脚本未清理用户输入,可能导致远程命令执行。
CVSS Information
N/A
Vulnerability Type
N/A