Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Multisuns EasyLog web+ - Path Traversal
Vulnerability Description
Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Multisuns EasyLog web+ 路径遍历漏洞
Vulnerability Description
Multisuns EasyLog web+是中国华鼎(Multisuns)公司的一款无人值守多回路数位电话录音系统。 Multisuns EasyLog web+ v1.13.2.8版本存在路径遍历漏洞,该漏洞源于特定 URL 中存在路径遍历,远程攻击者利用该漏洞可以绕过身份验证并下载任意系统文件。
CVSS Information
N/A
Vulnerability Type
N/A