Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payload in the txdata parameter, used in tx()/transcript(), or the catdata parameter, used in cat(). This vulnerability appears to have been fixed in 1.7.0.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Security Onion Solutions Squert 安全漏洞
Vulnerability Description
Security Onion Solutions Squert是一款用于查询和查看存储在Shuil数据库中的事件数据的Web应用程序。 Security Onion Solutions Squert 1.0.1版本至1.6.7版本中的.inc/callback.php文件存在安全漏洞。攻击者可通过向.inc/callback.php文件发送‘txdata’参数中带有载荷的Web请求利用该漏洞执行操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A