Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution
Vulnerability Description
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
LifeSize ClearSea 路径遍历漏洞
Vulnerability Description
LifeSize ClearSea是LifeSize公司的一个提供企业级视频通信与移动协作能力的统一通信平台。 LifeSize ClearSea 3.1.4版本存在路径遍历漏洞,该漏洞源于目录遍历,可能导致经过身份验证的攻击者通过操纵smartgui界面中的路径参数下载和上传任意文件,利用上传端点中的目录遍历序列将文件写入系统上的任意位置,实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A