Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zarafa Collaboration Platform 后置链接漏洞
Vulnerability Description
Zarafa Collaboration Platform(ZCP)是荷兰Zarafa公司的一套开源的电子邮件和日历软件。 ZCP 7.1.13之前版本和7.2.1之前7.2.x版本的provider/server/ECServer.cpp文件中存在安全漏洞。本地攻击者可通过对/tmp/zarafa-upgrade-lock URI实施符号链接攻击利用该漏洞写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A