脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
脆弱性説明
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. A technical fix is planned to be released.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
脆弱性タイプ
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
脆弱性タイトル
H3C SecPath F1000-C8300 输入验证错误漏洞
脆弱性説明
H3C H3C SecPath F1000-C8300是中国H3C公司的一系列面向中小型企业、园区网络出口和广域网分支的高性能云防火墙。 H3C SecPath F1000-C8300 20260522及之前版本存在安全漏洞,该漏洞源于文件/webui/?g=log_fw_nbc_mail_jsondata中参数subject操作不当,可能导致SQL注入。
CVSS情報
N/A
脆弱性タイプ
N/A