Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BlackBerry Link Remote File Access Feature 跨站请求伪造漏洞
Vulnerability Description
BlackBerry Link是加拿大黑莓(BlackBerry)公司的一套手机同步软件。该软件可通过USB或Wi-Fi在黑莓手机和电脑之间同步音乐、图片、视频等数据。 Windows平台上的BlackBerry Link 1.2.0.28及之前的版本和Mac OS X平台上的BlackBerry Link 1.1.1.26及之前的版本中存在跨站请求伪造漏洞,该漏洞源于程序对远程文件访问没有要求身份验证。远程攻击者可通过发送IPv6 WebDAV请求利用该漏洞读取或创建任意文件。
CVSS Information
N/A
Vulnerability Type
N/A