漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE
Vulnerability Description
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achieve remote code execution in the context of the NetSupport Manager connectivity service.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
NetSupport Manager 安全漏洞
Vulnerability Description
NetSupport Manager是NetSupport Manager公司的一款远程控制软件。 NetSupport Manager 14.12.0001之前版本存在安全漏洞,该漏洞源于Connectivity Server/Gateway PUTFILE请求处理程序存在任意文件写入,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A