漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
Vulnerability Description
KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
Web页面中服务端引用(SSI)转义处理不恰当
Vulnerability Title
KUNBUS PiCtory 安全漏洞
Vulnerability Description
KUNBUS PiCtory是KUNBUS公司的一个用于配置和管理 KUNBUS Revolution Pi 工业计算机的图形化软件工具。 KUNBUS PiCtory 2.11.1及之前版本存在安全漏洞,该漏洞源于文件名未转义,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A