在 dbgate 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1 及更早版本中发现了漏洞。该漏洞位于组件 “save-uploaded-file” 端点中 files.js 文件的 saveUploadedFile 函数。对参数 filePath/fileName 的恶意操纵会导致路径遍历(Path Traversal)漏洞。攻击者可以从远程发起攻击。该漏洞的利用代码已在公开渠道发布,可能被滥用。厂商此前已就此披露事项进行联系,但未以任何方式作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | dbgate | 6.8.0 |
cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100908 | 7.5 HIGH | Eyeplus p2pcam HTTP stack-based overflow |
| CVE-2026-101066 | 7.3 HIGH | dbgate Archive Link Creation archive.js createLink path traversal |
| CVE-2026-101005 | 7.3 HIGH | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request |
| CVE-2026-100909 | 7.3 HIGH | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery |
| CVE-2026-101069 | 6.5 MEDIUM | dbgate Export databaseConnections.js exportModelSql path traversal |
| CVE-2026-101068 | 6.5 MEDIUM | dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal |
| CVE-2026-101070 | 5.3 MEDIUM | dbgate Files Endpoint runners.js files path traversal |
| CVE-2026-100907 | 5.3 MEDIUM | Eyeplus p2pcam Service snapshot information disclosure |
| CVE-2026-100906 | 5.3 MEDIUM | Eyeplus ONVIF Device GetUsers information disclosure |
No comments yet