Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Atlassian Confluence 路径遍历漏洞
Vulnerability Description
Atlassian Confluence是澳大利亚Atlassian公司的一套专业的企业知识管理与协同软件,也可以用于构建企业WiKi。 Atlassian Confluence 1.3.5之前版本存在路径遍历漏洞。攻击者利用该漏洞通过“fileName”参数下载的任何文件(例如,SSH私钥)。
CVSS Information
N/A
Vulnerability Type
N/A