GFI Exinda AI 在 7.6.5 之前版本中,其诊断文件删除处理程序中存在路径遍历漏洞。 函数会接受以 为前缀的参数,并将这些参数的值直接追加到基础目录路径中,且未对目录遍历序列进行清理或校验。具有管理员权限的已认证攻击者可以利用该漏洞,在 root 用户上下文中删除系统中的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GFI Software | GFI ClearView | < 7.6.5 |
affected |
| GFI Software | GFI Exinda AI | < 7.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GFI Software | GFI Exinda AI | 0 ~ 7.6.5 | - |
|
| GFI Software | GFI ClearView | 0 ~ 7.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74237 | 6.5 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client |
| CVE-2026-74235 | 4.9 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler |
No comments yet