Froxlor 2.3.12 之前的版本在 SshKeys::add() 接口中未能正确验证多行 SSH 公钥,允许用户向 authorized_keys 文件中注入任意行。攻击者可以注入带有选项指令的恶意 SSH 密钥条目,从而获得持久的未授权访问权限,且该访问权限在密钥删除或撤销 SSH 访问权限后依然存在。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet