BugTracker.NET 的 SVN 集成组件中存在操作系统命令注入漏洞。该应用未对与存储库对应的字段值进行充分验证,便将其直接拼接到 svn.exe 命令中。具备管理员权限的已认证用户可将构造的恶意参数存储至数据库中,随后由版本比较功能处理这些参数。成功利用此漏洞可导致以应用程序所用账户的权限执行任意系统命令。要利用此漏洞,必须安装 svn.exe 且该服务能够调用它。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BugTracker.NET | BugTracker.NET | all versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92532 | 7.5 HIGH | Unrestricted Upload of File with Dangerous Type in BugTracker.NET |
| CVE-2026-92533 | 7.1 HIGH | Path Traversal in BugTracker.NET |
No comments yet