TUBITAK BILGEM 软件技术研究学院开发的 Pardus Pen 软件中存在命令参数分隔符未正确转义(即“参数注入”)漏洞,允许攻击者进行参数注入攻击。 该问题影响 Pardus Pen 4.2.1 版本之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TUBITAK BILGEM Software Technologies Research Institute | Pardus Pen | 0 ~ 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7863 | 8.4 HIGH | OS Command Injection in TUBITAK BILGEM's Pardus Software |
| CVE-2026-8303 | 7.8 HIGH | Privilege Escalation in TUBITAK BILGEM's Pardus-software |
| CVE-2026-8301 | 7.8 HIGH | OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair |
| CVE-2026-8304 | 5.5 MEDIUM | Information Disclosure in TUBITAK BILGEM's Pardus About |
No comments yet