Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Openwsman 路径遍历漏洞
Vulnerability Description
Openwsman是一套开源的WEB服务管理规范实现。 Openwsman 2.6.9及之前版本存在路径遍历漏洞,该漏洞源于openwsmand守护进程的工作路径被设置成了根路径。远程攻击者可通过访特制的HTTP请求利用该漏洞泄露任意文件。
CVSS Information
N/A
Vulnerability Type
N/A