Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
10-Strike Network Inventory Explorer Pro 9.31 - 'srvInventoryWebServer' Unquoted Service Path
Vulnerability Description
10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code with system-level permissions.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
未经引用的搜索路径或元素
Vulnerability Title
10-Strike Network Inventory Explorer Pro 安全漏洞
Vulnerability Description
10-Strike Network Inventory Explorer Pro是美国10-Strike公司的一个网络资产管理与审计工具。 10-Strike Network Inventory Explorer Pro 9.31版本存在安全漏洞,该漏洞源于srvInventoryWebServer服务存在未加引号的服务路径,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A