Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
UBIKA WAAP Gateway/Cloud 注入漏洞
Vulnerability Description
UBIKA WAAP Gateway/Cloud是UBIKA公司的一个管理企业级的应用程序安全性的解决方案。 UBIKA WAAP Gateway/Cloud 6.10及之前版本存在安全漏洞,该漏洞源于存在XPath注入,攻击者利用该漏洞可以通过窃取另一个连接用户的会话导致身份验证绕过。
CVSS Information
N/A
Vulnerability Type
N/A