Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cURL/libcURL SQL注入漏洞
Vulnerability Description
cURL是命令行传输文件工具,支持FTP、FTPS、HTTP、HTTPS、GOPHER、TELNET、DICT、FILE和LDAP。 cURL/libcURL 7.20.0至7.23.1版本中存在输入验证漏洞,攻击者可利用该漏洞向基于libcURL的应用程序中注入任意数据。该漏洞影响下列协议:IMAP、POP3和 SMTP。攻击成功将允许攻击者执行未授权操作,例如欺骗POP3客户端删除信息,或SMTP服务器发送意外信息,也可能执行其它攻击。
CVSS Information
N/A
Vulnerability Type
N/A