漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Neutralization of Directives in Dynamically Evaluated Code
Vulnerability Description
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to control the input to the function and execute attacker controlled commands.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
Eaton Intelligent Power Manager 代码注入漏洞
Vulnerability Description
Eaton Intelligent Power Manager(IPM)是美国伊顿(Eaton)公司的一款智能电源管理器,它支持从界面远程监视和管理网络中的多个设备。 Eaton Intelligent Power Manager 1.69之前版本存在代码注入漏洞,攻击者利用该漏洞控制函数的输入并执行攻击者控制的命令。
CVSS Information
N/A
Vulnerability Type
N/A