Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
S3 Browser 安全漏洞
Vulnerability Description
S3 Browser是一款适用于Amazon S3和Amazon CloudFront的Windows客户端应用程序,它主要用于数据检索和内容分发等。 S3 Browser 8.1.5之前版本中存在XML外部实体注入漏洞。远程攻击者可通过诱使用户借助S3协议连接到恶意的服务器利用该漏洞读取任意文件并获取NTLMv2散列值。
CVSS Information
N/A
Vulnerability Type
N/A