在 dbgate 7.3.1 及更早版本中检测到一处安全漏洞。该漏洞影响 Files Endpoint 组件中 packages/api/src/controllers/runners.js 文件的 files 函数。通过对参数 runid 的不当操控,攻击者可触发路径遍历(path traversal)漏洞。该攻击可在远程执行。漏洞利用方法已公开披露,可能被滥用。供应商已提前获知此漏洞披露信息,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | dbgate | 7.3.0 |
cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100908 | 7.5 HIGH | Eyeplus p2pcam HTTP stack-based overflow |
| CVE-2026-101067 | 7.3 HIGH | dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal |
| CVE-2026-101066 | 7.3 HIGH | dbgate Archive Link Creation archive.js createLink path traversal |
| CVE-2026-101005 | 7.3 HIGH | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request |
| CVE-2026-100909 | 7.3 HIGH | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery |
| CVE-2026-101069 | 6.5 MEDIUM | dbgate Export databaseConnections.js exportModelSql path traversal |
| CVE-2026-101068 | 6.5 MEDIUM | dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal |
| CVE-2026-100907 | 5.3 MEDIUM | Eyeplus p2pcam Service snapshot information disclosure |
| CVE-2026-100906 | 5.3 MEDIUM | Eyeplus ONVIF Device GetUsers information disclosure |
No comments yet