Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mutiny 多个目录遍历漏洞
Vulnerability Description
Mutiny是英国Mutiny公司的一个网络监控设备。 Mutiny 5.0-1.11之前的版本中的Frontend中的EditDocument servlet中存在多个目录遍历漏洞。远程经过授权的攻击者可通过(1)UPLOAD操作中的uploadPath参数;(2)DELETE,(3)CUT或(4)COPY操作中的paths[]参数;或(5)CUT或(6)COPY操作中的newPath参数利用这些漏洞上传任意程序,读取任意文件,或造成拒绝服务(文件删除或重命名)。
CVSS Information
N/A
Vulnerability Type
N/A