漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
The application evaluate UNC path in workspace name
Vulnerability Description
Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization, the application does not sanitize the workspace name. The cause issue if the workspace name evaluate to a UNC path since it's allowed for the name to containt `\` char. If the UNC path is invalid (or the targeted resource is not available) the application become unresponsive otherwise the system will interact with the mounted UNC path allowing the attacker to retrieve to [`NTLM`] hash.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
路径遍历:’\UNCsharename'(WindowsUNC共享)
Vulnerability Title
Scille Parsec 路径遍历漏洞
Vulnerability Description
Scille Parsec是Scille团队的一款基于云的应用程序,用于简单且加密安全的文件共享。 Scille Parsec 3.3.3-rc.0之前版本存在路径遍历漏洞,该漏洞源于未对工作空间名称进行清理,如果工作空间名为UNC路径,在Windows文件系统中创建挂载点时可能导致应用程序无响应,或允许攻击者通过交互获取NTLM哈希。
CVSS Information
N/A
Vulnerability Type
N/A