漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
D-Link DAR-8000-10 importhtml.php deserialization
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-263747. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
可信数据的反序列化
Vulnerability Title
D-Link DAR-8000 代码问题漏洞
Vulnerability Description
D-Link DAR-8000是中国友讯(D-Link)公司的上网行为审计网关。 D-Link DAR-8000-10 20230922及之前版本存在代码问题漏洞,该漏洞源于文件/importhtml.php的参数sql会导致反序列化。
CVSS Information
N/A
Vulnerability Type
N/A