Heimdall Data 数据库代理 uploadJar 目录遍历远程代码执行漏洞。该漏洞允许远程攻击者在受影响的 Heimdall Data 数据库代理安装中执行任意代码。利用此漏洞需要进行身份验证。 该特定漏洞存在于 uploadJar 方法中。问题源于在将用户提供的路径用于文件操作之前,未对其进行适当验证。攻击者可利用此漏洞,以 root 权限上下文执行代码。此漏洞对应 ZDI-CAN-28603。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Heimdall Data | Database Proxy | 25.03.01.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Heimdall Data | Database Proxy | 25.03.01.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet