Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ServiceTonic Helpdesk Software代码问题漏洞
Vulnerability Description
ServiceTonic Helpdesk Software是西班牙ServiceTonic公司的一款多功能服务管理软件。 ServiceTonic Helpdesk 9.0.35937之前版本存在安全漏洞,该漏洞源于任意文件上传服务导入功能,攻击者可利用该漏洞通过上传在相对路径中提取文件的zip来执行JSP代码。
CVSS Information
N/A
Vulnerability Type
N/A