Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
India Goods and Services Tax Network Offline Utility工具安全漏洞
Vulnerability Description
India Goods and Services Tax Network(GSTN) Offline Utility tool是印度Goods and Services Tax Network(商品和服务税务网)的一款离线实用程序工具。 India GSTN Offline Utility工具1.2之前的版本中的GSTN_offline_tool存在安全漏洞。本地攻击者可通过将winstart-server.vbs替换成任意的VBScript代码利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A