Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cybele Software Thinfinity VirtualUI 信息泄露漏洞
Vulnerability Description
Cybele Software Thinfinity VirtualUI是美国Cybele Software公司的一款支持将远程Windows应用程序嵌入到标准Web应用程序中,从而可以与Javascript编程进行双向交互的解决方案。 Cybele Software Thinfinity VirtualUI 存在信息泄露漏洞,该漏洞源于Thinfinity VirtualUI 受到cmd站点中参数“Addr”信息泄露漏洞的影响。攻击者可利用该漏洞向其他系统发送请求的能力可以让脆弱的服务器过滤web服务器
CVSS Information
N/A
Vulnerability Type
N/A