Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
F5 BIG-IP 路径遍历漏洞
Vulnerability Description
F5 BIG-IP是美国F5公司的一款集成了网络流量管理、应用程序安全管理、负载均衡等功能的多合一网络设备。 F5 BIG-IP 10.2.1及之前版本中存在目录遍历漏洞,该漏洞源于tmui/Control/jspmap/tmui/system/archive/properties.jsp脚本和tmui/Control/form URL没有充分过滤‘name’参数。本地攻击者可借助目录遍历字符‘..’利用该漏洞以‘Resource Administrator’或‘Administrator’角色枚举和删除
CVSS Information
N/A
Vulnerability Type
N/A