漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
Vulnerability Description
A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation of the argument troiaCode results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Canias ERP 命令注入漏洞
Vulnerability Description
Canias ERP是瑞士Canias公司的一个覆盖企业资源计划与业务流程管理的综合管理系统。 Canias ERP 8.03版本存在命令注入漏洞,该漏洞源于组件RMI Interface中函数Runtime.getRuntime.exec对参数troiaCode的操作,可能导致OS命令注入。
CVSS Information
N/A
Vulnerability Type
N/A