Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CSLA .NET is vulnerable to Remote Code Execution via WcfProxy
Vulnerability Description
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
CSLA .NET 代码问题漏洞
Vulnerability Description
CSLA .NET是Marimer LLC开源的一个软件开发框架。可帮助用户为应用程序构建可重用、可维护的面向对象的业务层。 CSLA .NET 5.5.4及之前版本存在代码问题漏洞,该漏洞源于反序列化不当,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A