在版本 cf882dabea3ed91cef016cdd115e5426315665a2 及更早版本的 GH05TCREW PentestAgent 中发现一个漏洞。该问题影响组件 LocalRuntime 中文件 runtime/runtime.py 里的 LocalRuntime.execute_command 函数。对输入进行操纵可能导致操作系统命令注入攻击。攻击者可远程发起该攻击。利用方法已经公开,可能被实际利用。修复此问题的拉取请求(pull request)目前等待被接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GH05TCREW | PentestAgent | cf882dabea3ed91cef016cdd115e5426315665a2 |
cpe:2.3:a:gh05tcrew:pentestagent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet