漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Jahastech NxFilter Bind Request ldap injection
Vulnerability Description
A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipulation leads to ldap injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-248267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入)
Vulnerability Title
NxFilter 注入漏洞
Vulnerability Description
NxFilter是NxFilter公司的一个轻量级的 DNS 过滤器。 Jahastech NxFilter 4.3.2.5版本存在注入漏洞,该漏洞源于文件user,adap.jsp?actionFlag=test&id=1会导致LDAP注入。
CVSS Information
N/A
Vulnerability Type
N/A