漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
Vulnerability Description
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the FileProxySource proxy loading feature. Attackers can upload malicious script files as proxy sources, causing the server to execute the scripts and return output as proxy lines, resulting in arbitrary command execution on the host as the process user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
OpenBullet2 操作系统命令注入漏洞
Vulnerability Description
OpenBullet2是openbullet个人开发者的一个跨平台自动化测试与数据抓取工具。 OpenBullet2 0.3.2及之前版本存在操作系统命令注入漏洞,该漏洞源于FileProxySource代理加载功能,可能导致经过身份验证的用户通过上传脚本文件执行任意命令,攻击者可将恶意脚本文件作为代理源上传,导致服务器执行脚本并返回输出。
CVSS Information
N/A
Vulnerability Type
N/A