漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unsanitized input in language form field
Vulnerability Description
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized
before being used and can be misused to include an arbitrary file in the
PHP code allowing an attacker to do anything as the web server user.
This flaw requires the attacker to be authenticated with a valid user account.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface 安全漏洞
Vulnerability Description
iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface都是iFAX公司的产品。iFAX AvantFAX是一个Web应用程序,允许用户在任何平台上查看和发送传真,而无需安装特殊软件。iFAX HylaFAX Enterprise Web Interface是一个基于 Web 的应用程序,用于管理 HylaFAX 上的传真。 iFAX AvantFAX和iFAX HylaFAX Enterprise Web Interface存在安全漏洞,该漏洞源于语言表单元
CVSS Information
N/A
Vulnerability Type
N/A