Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
卓源软件 Jeesite 代码问题漏洞
Vulnerability Description
卓源软件 Jeesite是中国卓源软件公司的一套开源的Java EE企业级快速开发平台。该平台包括系统权限组件、数据权限组件、数据字典组件、核心工具组件、视图操作组件、工作流组件和代码生成组件等。 Jeesite 1.2.7版本存在安全漏洞,该漏洞源于此版本存在java反序列化漏洞,攻击者利用该漏洞通过rememberMe参数执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A