Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GestioIP 3.0 ip_checkhost.cgi RCE
Vulnerability Description
A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to the 'ip' parameter allows attackers to execute arbitrary shell commands on the server via embedded base64-encoded payloads. Authentication may be required depending on deployment configuration.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
GestioIP 安全漏洞
Vulnerability Description
GestioIP是GestioIP公司的一款基于 Web 的 IPv4/IPv6 地址管理软件。 GestioIP 3.0 commit ac67be及之前版本存在安全漏洞,该漏洞源于ip参数未经验证,可能导致远程命令执行。
CVSS Information
N/A
Vulnerability Type
N/A