Spotweb 版本 1.5.8 及之前版本中,存在一个位于 NZB 处理程序中的操作系统命令注入漏洞。远程攻击者可通过发布带有恶意标题的“spots”(新闻组消息)来执行任意系统命令。攻击者能够在 Usenet 上发布带有 shell 元字符的恶意标题的“spots”,这些元字符在后续操作中被未经转义地替换到 变量中,并在用户下载该 spot 时传入 函数执行,从而以 Spotweb PHP 进程的权限运行恶意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet