Liman 是一款开源服务器管理软件。在 2.2.2 - 1103 版本之前,日志轮转配置端点存在操作系统命令注入漏洞,经过身份验证的管理员可以在 Liman 服务器上执行任意操作系统命令。 参数被直接嵌入 shell 命令中且未经过清洗,使得攻击者可以通过单引号注入实现 shell 转义。该漏洞已在 2.2.2 - 1103 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet