Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Remote code execution in Proxyee-Down
Vulnerability Description
Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM attack or by hosting a malicious extension) may be able to run arbitrary commands on the system running Proxyee-Down. For more details including a PoC see the referenced GHSL-2021-053. As of the writing of this CVE there is currently no patched version.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
proxy-down 操作系统命令注入漏洞
Vulnerability Description
proxyee-down是一款开源的免费 HTTP 高速下载器,底层使用netty开发,支持自定义 HTTP 请求下载且支持扩展功能,可以通过安装扩展实现特殊的下载需求。 proxy-down存在操作系统命令注入漏洞,该漏洞源于能够提供扩展脚本的攻击者可利用该漏洞(例如:通过MiTM攻击或托管恶意扩展)可能能够在运行Proxyee-Down的系统上运行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A