Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OwnCloud Server 操作系统命令注入漏洞
Vulnerability Description
ownCloud是德国ownCloud公司的一套免费且开源的个人云存储解决方案,它提供文件管理、音乐存储、日历等功能。ownCloud server是一个服务器版。 OwnCloud Server 8.1.2之前版本的external legacy SMB存储功能中存在安全漏洞,该漏洞源于Server.php脚本中的‘listShares’函数和Share.php脚本中的‘connect’或‘read’函数没有充分过滤‘user’参数中的shell元字符。远程攻击者可利用该漏洞执行任意SMB命令。
CVSS Information
N/A
Vulnerability Type
N/A