YaCy Search Server 版本 1.941 及更早版本存在 XML 外部实体注入漏洞。该漏洞存在于 SVG、FreeMind 和 OpenSearch 解析器中,这些解析器未禁用外部实体解析。攻击者可以发布包含指向本地文件的 SYSTEM 实体的 DOCTYPE 声明的恶意文档,从而使爬虫将文件内容外泄到可搜索索引中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yacy | yacy_search_server | ≤ 1.941 |
affected |
3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yacy | yacy_search_server | 0 ~ 1.941 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet