在 David-Crty 开发的 databasement 软件(版本 1.7.1 及更早)中发现了一个漏洞。该漏洞影响 文件中的函数(对应 GitHub Pull Request #511),位于 database-servers API 端点组件中。攻击者可通过操纵 参数触发路径遍历(Path Traversal)漏洞。该攻击可远程发起,但具有较高的复杂度,利用难度较大。相关漏洞信息已公开披露,可能被用于实际攻击。升级到 1.7.2 版本可修复此问题,建议立即升级受影响组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| David-Crty | databasement | 1.7.0 |
cpe:2.3:a:david-crty:databasement:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet