Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Neo4J 跨站请求伪造漏洞
Vulnerability Description
Neo4j是美国Neo4j公司的一款基于Java的且完全兼容ACID的图形数据库,它支持数据迁移、附加组件等。 Neo4J 1.9.2版本中存在跨站请求伪造漏洞。远程攻击者可通过向db/data/ext/GremlinPlugin/graphdb/execute_script页面或db/manage/server/console/页面发送请求利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A