Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
D-Link DNS-320L和DNS-327L 安全漏洞
Vulnerability Description
D-Link DNS-320L和DNS-327L都是友讯(D-Link)公司的具有云功能的网络存储器。 D-Link DNS-320L 1.04b12之前的版本和DNS-327L 1.03b04 Build0119之前的版本中的web/web_file/fb_publish.php脚本存在安全漏洞,该漏洞源于程序没有对请求进行身份验证。远程攻击者可利用该漏洞获取任意图片,并将图片发布到任意Facebook个人资料上。
CVSS Information
N/A
Vulnerability Type
N/A