漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kennnyshiwa-cogs vulnerable to Remote Code Execution in Tickets Module
Vulnerability Description
Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-cogs. This exploit allows discord users to craft a message that can reveal sensitive and harmful information. Users can upgrade to version 5a84d60018468e5c0346f7ee74b2b4650a6dade7 to receive a patch or, as a workaround, unload tickets to render the exploit unusable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
kennnyshiwa-cogs 代码注入漏洞
Vulnerability Description
kennnyshiwa-cogs是一个应用软件。从Intel的ARK数据库中检索CPU的信息。 kennyshiwa -cogs的Tickets模块存在代码注入漏洞。该漏洞可泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A