ADM 的 start-page-loader.cgi 中存在 HTTP 头注入漏洞,允许未经身份验证的远程攻击者读取主机系统上的任意文件。攻击者可通过通过 state 参数发送包含注入头的精心构造的 HTTP 请求,利用底层 Web 服务器的 X-Sendfile 机制,在无需身份验证的情况下检索敏感文件。 受影响的版本包括:ADM 4.1.0 至 ADM 4.3.3.RWC1,以及 ADM 5.0.0 至 ADM 5.1.4.RL21。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ASUSTOR Inc. | ADM | 5.0.0 ~ 5.1.4.RL21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet