漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation leads to read access, and write access (depending on file permissions), to the symlink target. Third, the attacker can import a Git repository that contains a symlink, similarly leading to read and write access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
b3log Wide 注入漏洞
Vulnerability Description
b3log Wide是一套基于Web的Go语言集成开发环境(IDE)。 b3log Wide 1.6.0之前版本中存在安全漏洞。攻击者可利用该漏洞访问任意文件。
CVSS Information
N/A
Vulnerability Type
N/A