Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RuvarOA 安全漏洞
Vulnerability Description
RuvarOA是中国璐华(Ruvar)公司的一个办公自动化系统。 RuvarOA v6.01 版本和 v12.01 版本存在安全漏洞,该漏洞源于 /WorkFlow/OfficeFileUpdate.aspx 文件存在 SQL 注入漏洞。
CVSS Information
N/A
Vulnerability Type
N/A