Sharp(以及东芝 Tec 重新品牌化的)多功能打印机存在一个未经身份验证的本地文件包含漏洞,允许远程攻击者通过操纵 端点中的 参数来读取任意文件。攻击者可以提交目录遍历序列(例如 ),以访问预期手册目录之外的文件,包括 、包含凭据的核心转储文件以及系统配置文件。该漏洞的利用证据最早由 Shadowserver 基金会于 2024 年 7 月 30 日发现。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sharp Corporation | Multiple Multifunction Printers | * | - |
|
| Toshiba Tec Corporation | Multiple Multifunction Printers | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet