Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squaredup安全漏洞
Vulnerability Description
Squaredup是英国Squaredup公司的一个可为云环境提供数据监控功能的Web服务。 SquaredUp for SCOM 5.2.1.6654版本存在安全漏洞,该漏洞源于System/Maintenance 中的下载日志功能缺少对于文件包含的限制(在处理由经过身份验证的管理员用户下载的日志文件中的远程输入时),导致能够读取服务器文件系统上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A