Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
geckodriver 跨站请求伪造漏洞
Vulnerability Description
geckodriver是一个应用软件。提供了WebDriver 协议描述的 HTTP API来与 Gecko 浏览器进行通信。 geckodriver在0.27.0之前存在安全漏洞,该漏洞源于缺少对geckodriver中的Content-Type头的检查可能会导致CSRF漏洞,当与专门准备的请求配对时,可能会导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A