Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HCL Sametime is susceptible a file transfer service vulnerability
Vulnerability Description
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
HCL Technologies HCL Sametime 代码问题漏洞
Vulnerability Description
HCL Sametime是HCL Technologies的一个会议解决方案。 HCL Technologies HCL Sametime 11.6版本存在安全漏洞,该漏洞源于应用中的用户SID 可以被修改。攻击者可以利用该漏洞修改SID实现任意文件上传或目录删除从而导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A