Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Subsonic 安全漏洞
Vulnerability Description
Subsonic是软件开发者Sindre Mehus开发和维护的一个媒体文件托管平台。 Subsonic 6.1.3版本中存在安全漏洞。攻击者可通过诱使用户访问加载有SWF文件的网站利用该漏洞检索敏感用户的信息。
CVSS Information
N/A
Vulnerability Type
N/A