NoMachine getstat 命令注入远程代码执行漏洞。此漏洞允许远程攻击者在受影响的 NoMachine 安装系统中执行任意代码,但利用该漏洞需要身份验证。 该漏洞存在于默认监听 TCP 端口 4000 的 Web 服务中。问题的根源在于:在执行系统调用之前,未对用户提供的字符串进行适当的验证。攻击者可利用此漏洞,在服务账户的上下文环境中执行代码。 此漏洞对应编号为 ZDI-CAN-30634。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet