漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Arbitrary File Overwrite
Vulnerability Description
The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore an arbitrary file can be overwritten. The file can be controlled by an authenticated attacker, the content cannot be controlled. It is possible to overwrite all files for which the webserver has write access. It is required to supply a relative path (path traversal).
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
HAWKI 安全漏洞
Vulnerability Description
HAWKI是德国HAWK Digital Environments团队的一个基于 OpenAI API 的大学教学界面。 HAWKI存在安全漏洞,该漏洞源于没有正确筛选POST参数,导致存在路径遍历漏洞。攻击者可利用该漏洞覆Web服务器具有写权限的所有文件。
CVSS Information
N/A
Vulnerability Type
N/A