Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AutoFORM PDM Archive安全绕过漏洞
Vulnerability Description
AutoFORM PDM Archive 7.0之前版本的实现中存在漏洞,该漏洞源于允许JXC控制台认证用户账户。远程认证用户可利用该漏洞通过/jmx-console URI绕过预期的访问限制,然后通过JBoss远程部署机制上传并执行任意JSP代码。
CVSS Information
N/A
Vulnerability Type
N/A