Ruijie Networks RG-UAC是中国锐捷网络(Ruijie Networks)公司的一个上网行为管理与审计产品。用于解决互联网审计问题。 Ruijie Networks RG-UAC 1.0版本存在操作系统命令注入漏洞,该漏洞源于/view/userAuthentication/SSO/commit.php 存在安全问题,通过参数 ad_log_name 导致系统命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6184 | 6.3 MEDIUM | Ruijie RG-UAC reboot_commit.php os command injection |
| CVE-2024-6185 | 6.3 MEDIUM | Ruijie RG-UAC commit.php get_ip_addr_details os command injection |
| CVE-2024-6187 | 6.3 MEDIUM | Ruijie RG-UAC sub_commit.php os command injection |
No comments yet