Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with root privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Draytek VigorConnect 代码问题漏洞
Vulnerability Description
Draytek VigorConnect是中国居易科技(Draytek)公司的一种易于使用、重量轻、用于 DrayTek 产品的单站点中央管理系统。 Draytek VigorConnect 中存在代码问题漏洞,该漏洞源于产品的DownloadFileServlet的文件上传功能未对文件名称或权限做有效检查。攻击者可通过该漏洞将漏洞文件上传到目标系统的任意位置。以下产品及版本受到影响: Draytek VigorConnect 1.6.0-B3版本。
CVSS Information
N/A
Vulnerability Type
N/A