漏洞描述:代码下载时未进行完整性校验、从不可信的控制域中引入功能,以及对敏感信息进行明文传输的安全漏洞,存在于 Windows 系统上的 Ozols Grupa OZOLS 软件中,其根本原因在于一个已废弃的自动更新域名。受影响的组件包括自动更新通道,具体为:OzolsSQL 客户端更新路径、 SQL Server Agent 作业(@subsystem = N'ActiveScripting')以及 serv_update.vbs 脚本。 该问题影响 OZOLS 1.1.1233 之前的所有版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ozols Grupa | OZOLS | < 1.1.1233 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ozols Grupa | OZOLS | 0 ~ 1.1.1233 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet