Spug 3.4.0 及之前版本中存在一个远程代码执行漏洞,位于 函数中。该函数将用户提供的监控地址未经校验直接插入到 shell 命令中。拥有监控权限的已认证用户可以通过 端点注入 shell 元字符,从而以 Spug 进程用户身份执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet