Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
3S CoDeSys ‘CmbWebserver.dll’模块权限许可和访问控制漏洞
Vulnerability Description
3S CoDeSys 3.4 SP4 Patch 2 控制服务的CmbWebserver.dll模块中存在漏洞。远程攻击者可利用该漏洞在HTTP GET请求时,借助\ (反斜杠) 字符指定一个不存在的目录,从而在web根目录下创建任意目录。
CVSS Information
N/A
Vulnerability Type
N/A