DbGate 的 控制器未能校验 参数,导致经过身份验证的用户可通过 协议解析机制读取和写入任意文件。攻击者可利用 方法绕过目录限制,访问敏感文件,包括存储在连接配置中的加密数据库凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet