Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fimage_jsp servlet, which listens on TCP port 8081 by default. When parsing the id parameter, the process does not properly validate user-supplied data, which can allow for the upload of files. An attacker can leverage this vulnerability to execute code under the context of Administrator. Was ZDI-CAN-5117.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
NetGain Enterprise Manager 安全漏洞
Vulnerability Description
Netgain Enterprise Manager(EM)是新加坡网利系统(NetGain Systems)公司的一套IT资产监控管理软件。 NetGain Enterprise Manager 7.2.730 build 1034版本中的org.apache.jsp.u.jsp.db.save_005fimage_jsp servlet存在远程代码执行漏洞,该漏洞源于进程没有正确的验证用户提交的数据。远程攻击者可利用该漏洞上传文件,在管理员的上下文中执行代码。
CVSS Information
N/A
Vulnerability Type
N/A