GFI Exinda AI 在 7.6.5 之前的版本中,其“Tools Iperf Client”功能存在一个参数注入漏洞。 函数在未对输入进行清理的情况下,使用 和 参数构建 命令,从而允许注入任意的 标志。拥有最低权限(Unprivileged)的经过身份验证的攻击者可以通过传入 标志,读取系统上的任意文件,并将其内容传输到攻击者控制的服务器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GFI Software | GFI ClearView | < 7.6.5 |
affected |
| GFI Software | GFI Exinda AI | < 7.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GFI Software | GFI Exinda AI | 0 ~ 7.6.5 | - |
|
| GFI Software | GFI ClearView | 0 ~ 7.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74236 | 6.5 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler |
| CVE-2026-74235 | 4.9 MEDIUM | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler |
No comments yet