Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
prolink SNMP Web Pro 安全漏洞
Vulnerability Description
prolink SNMP Web Pro是prolink公司的一个网络检测设备。 prolink SNMP Web Pro 1.1版本存在安全漏洞,该漏洞源于未经验证的目录遍历,可能导致读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A