Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to upload malicious files via crafted HTTP requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Q-Free MAXTIME Suite 代码问题漏洞
Vulnerability Description
Q-Free MAXTIME Suite是Q-Free公司的一个用于本地交通信号管理的软件套件。 Q-Free MAXTIME Suite 2.11.0版本及之前版本存在代码问题漏洞,该漏洞源于未限制危险类型上传的文件。攻击者利用该漏洞可以通过特制的HTTP请求上传恶意文件。
CVSS Information
N/A
Vulnerability Type
N/A