Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Missing Authorization in Hydrosystem Control System
Vulnerability Description
Hydrosystem Control System does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.This issue was fixed in Hydrosystem Control System version 9.8.5
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Hydrosystem Control System 安全漏洞
Vulnerability Description
Hydrosystem Control System是美国Hydrosystem公司的一个工业水处理与流体控制监测系统。 Hydrosystem Control System 9.8.5之前版本存在安全漏洞,该漏洞源于未对某些目录强制执行授权,可能导致未经授权的攻击者读取目录中的所有文件并执行部分文件,甚至直接在连接的数据库上运行PHP脚本。
CVSS Information
N/A
Vulnerability Type
N/A