漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability
Vulnerability Description
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.
CVSS Information
N/A
Vulnerability Type
保护机制失效
Vulnerability Title
Dropbox desktop application 安全漏洞
Vulnerability Description
Dropbox desktop application是美国Dropbox公司的一款开源的、跨平台的文件在线存储、同步、共享应用程序。 Dropbox desktop application存在安全漏洞,该漏洞源于共享文件夹的处理中存在特定缺陷,允许远程攻击者绕过 Mark-of-the-Web 保护机制,攻击者利用该漏洞可能在当前用户的环境中执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A