漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ALEAPP NQ Vault Artifact Parser Path Traversal
Vulnerability Description
ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a database directly as the output filename, allowing arbitrary file writes outside the report output directory. An attacker can embed a path traversal payload such as ../../../outside_written.bin in the database to write files to arbitrary locations, potentially achieving code execution by overwriting executable files or configuration.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Android Logs Events And Protobuf Parser 路径遍历漏洞
Vulnerability Description
Android Logs Events And Protobuf Parser是Brigs个人开发者的一个安卓日志与协议缓冲区解析工具。 Android Logs Events And Protobuf Parser 3.4.0及之前版本存在路径遍历漏洞,该漏洞源于NQ_Vault.py解析器使用来自数据库的攻击者可控file_name_from值直接作为输出文件名,可能导致任意文件写入报告输出目录之外的位置。
CVSS Information
N/A
Vulnerability Type
N/A