Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nmap 任意文件写入漏洞
Vulnerability Description
Nmap(Network Mapper)是美国软件开发者Gordon Lyon所研发的一套用于网络发现(Network Discovery)和安全审计(Security Auditing)的网络安全工具,该工具可对操作系统、端口开放情况与设备类型等进行详细检测。 NMap 6.40之前的版本中的http-domino-enum-passwords.nse脚本中存在安全漏洞,当脚本设置domino-enum-passwords.idpath参数时,远程攻击者可借助FullName参数,利用该漏洞写入任意文件
CVSS Information
N/A
Vulnerability Type
N/A