Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rukovoditel 代码问题漏洞
Vulnerability Description
Rukovoditel是Rukovoditel团队的一套基于Web的开源项目管理软件。该软件具有项目管理、客户关系管理等功能。 Rukovoditel 2.5.2版本中存在安全漏洞。攻击者可通过更改content-type值利用该漏洞将任意文件上传到服务器并执行命令。
CVSS Information
N/A
Vulnerability Type
N/A