Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Local Privilege Escalation in Nimble Commander <= v1.6.0, Build 4087
Vulnerability Description
Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such as changing permissions and ownership, obtaining a handle (file descriptor) of an arbitrary file, and terminating processes, among other operations.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
Softvelum Nimble Commander 安全漏洞
Vulnerability Description
Softvelum Nimble Commander是Softvelum公司的一个媒体服务器软件。用于将实时和点播视频和音频流式传输到台式计算机、 移动设备、连接互联网的电视等。 Softvelum Nimble Commander 存在安全漏洞,该漏洞源于在执行操作之前对客户端的授权进行了不正确或不充分的验证。攻击者利用该漏洞可以提升权限。
CVSS Information
N/A
Vulnerability Type
N/A