Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper Neutralization in Altitude Communication Server
Vulnerability Description
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
CVSS Information
N/A
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Altitude Communication Server 注入漏洞
Vulnerability Description
Altitude Communication Server是美国Altitude公司的一个IP联络中心软件。 Altitude Communication Server v8.5.3290.0版本存在注入漏洞,该漏洞源于对HTTP请求中Host标头的操作,可能导致重定向到任意URL或修改基础URL以诱骗受害者向恶意网站发送登录凭据。
CVSS Information
N/A
Vulnerability Type
N/A