数字与信息局(DIA)的 eObčanka-Identifikace 在 macOS 上存在操作系统命令注入(OS command injection)漏洞,由于未对操作系统命令中使用的特殊元素进行恰当中和处理,攻击者可以注册自定义 URL 方案(czeeopauth://)以执行参数化应用。在 3.6.0 版本之前,传入的 URL 参数通过字符串拼接传递给已编译的 AppleScript 封装器,且缺乏充分的清洗(sanitization),从而导致该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ministry of the Interior (MVČR) | eObčanka-Identifikace | 0 ~ 3.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet