Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Antsle antman 安全漏洞
Vulnerability Description
Antsle antman是美国Antsle公司的一款私有云服务器产品。 Antsle antman 0.9.1a之前版本中存在安全漏洞,该漏洞源于登录进程使用了Java的ProcessBuilder类,并且bash脚本在调用antsle-auth时没有充分的过滤输入。远程攻击者可借助‘username’和‘password’参数中的无效字符利用该漏洞绕过身份验证,获取root权限。
CVSS Information
N/A
Vulnerability Type
N/A