UAC(类 Unix 系统日志采集器)在 3.3.0 之前的版本中存在命令注入漏洞。该漏洞位于 函数中,在通过 执行命令之前,foreach 命令的输出行被直接通过 替换到命令字符串中,但未进行适当的转义处理。攻击者可以通过构造包含 shell 元字符(如命令替换语法或分号)的恶意文件名或采集定义,从而在分析师的主机上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-41449 | 7.8 HIGH | UAC < 3.3.0 Command Injection via run_command.sh |
| CVE-2026-41451 | 7.8 HIGH | UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh |
No comments yet