Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
User-Friendly SVN 安全漏洞
Vulnerability Description
User-Friendly SVN(USVN)是USVN团队的一套基于Web的Subversion代码库的配置工具。该工具提供创建新项目、管理授权用户列表等功能。 User-Friendly SVN v1.0.12之前版本存在安全漏洞,该漏洞源于对用户的输入验证不当。攻击者利用该漏洞通过字段“siteTitle”、“siteIco”和“siteLogo”执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A