Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
myVesta 命令注入漏洞
Vulnerability Description
myvesta myVesta是myvesta个人开发者的一款嵌入式Web服务器软件。 myVesta存在命令注入漏洞,该漏洞源于在删除FTP用户名时,对v_ftp_user参数处理不当,可能导致低权限用户插入任意命令,从而以管理员用户身份执行命令或接管管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A