Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apereo Bedework bw-webdav 安全漏洞
Vulnerability Description
Apereo Bedework bw-webdav是一款通用Webdav服务器。该产品主要用于与后端交互以访问资源。 Apereo Bedework bw-webdav 4.0.3之前版本中存在安全漏洞。攻击者可利用该漏洞实施XML外部实体注入攻击,读取本地文件。
CVSS Information
N/A
Vulnerability Type
N/A