在 GreyDGL PentestGPT 1.0.0 及之前版本中发现了一个漏洞。该漏洞影响“网页抓取”(Web-Page Crawling)组件中未知的代码部分。通过操纵参数 Traceback,可导致注入攻击。此攻击可远程执行,且攻击复杂度较高,利用难度较大。该漏洞的利用代码已被公开披露,可能被恶意利用。相关 GitHub 问题已以“不计划修复”(not planned)标签关闭。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GreyDGL | PentestGPT | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GreyDGL | PentestGPT | 1.0 |
cpe:2.3:a:greydgl:pentestgpt:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet