GFI Exinda AI 在 7.6.5 版本之前存在路径遍历漏洞,位于系统维护配置下载处理程序中。 函数接受以 为前缀的参数,并将它们的值直接拼接到基础配置目录路径之后,而未对目录遍历序列(如 )进行清理。拥有管理员权限的已认证攻击者可以利用该漏洞,在 root 用户上下文中读取系统中的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GFI Software | GFI ClearView | < 7.6.5 |
affected |
| GFI Software | GFI Exinda AI | < 7.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GFI Software | GFI Exinda AI | 0 ~ 7.6.5 | - |
|
| GFI Software | GFI ClearView | 0 ~ 7.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74236 | 6.5 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler |
| CVE-2026-74237 | 6.5 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client |
No comments yet