漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection
Vulnerability Description
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Dan SIP 命令注入漏洞
Vulnerability Description
Dan SIP是Dan个人开发者的一款基于 Raspberry Pi 的免费 Python 程序,用于控制灌溉系统(喷灌、滴灌、水培等)。 Dan SIP 5.2.16及之前版本存在命令注入漏洞,该漏洞源于可选插件cli_control中存在命令注入漏洞,允许未经身份验证的攻击者或跨站请求伪造攻击者通过插件HTTP端点存储恶意有效载荷,并通过激活相关灌溉站执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A