2.2.6 和 3.0.2 版本中的 函数存在参数注入漏洞,允许攻击者向 Info-ZIP 后端注入任意参数。攻击者可通过提供恶意的目标路径并结合构造的源条目,以 Node.js 进程的权限执行任意命令。该问题已在 2.2.7 和 3.0.3 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet