漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SolarWinds Serv-U FTP Service Directory Traversal Remote Code Execution Vulnerability
Vulnerability Description
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
SolarWinds Serv-U 路径遍历漏洞
Vulnerability Description
SolarWinds Serv-U是美国SolarWinds公司的一款 FTP(文件传输协议)服务器软件。 SolarWinds Serv-U 15.4.2及之前版本存在路径遍历漏洞,该漏洞源于根据授予经过身份验证的用户的权限,可以执行远程代码。
CVSS Information
N/A
Vulnerability Type
N/A