Duplicacy 在版本 3.2.5 及之前版本中存在路径遍历漏洞,其“还原”功能未对从快照文件中反序列化的条目路径进行充分验证。攻击者可以构造包含目录遍历序列(如 )的恶意快照条目,从而将文件写入还原目录之外的任意位置(该位置需对执行还原操作用户可访问)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gilbertchen | duplicacy | ≤ 3.2.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gilbertchen | duplicacy | 0 ~ 3.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet