Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NeDi 操作系统命令注入漏洞
Vulnerability Description
NeDi是一款网络设备发现工具,它主要用于查看设备信息、检测设备状态等。 NeDi 1.7Cp3之前版本中的Nodes-Traffic.php文件、Devices-Graph.php文件和drawmap.php文件存在操作系统命令注入漏洞。攻击者可借助‘flt’、‘dv’或‘tit’参数利用该漏洞在服务器上执行代码。
CVSS Information
N/A
Vulnerability Type
N/A