漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Arbitrary file overwrite through certificate update functionality
Vulnerability Description
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
EVbee DC-80 输入验证错误漏洞
Vulnerability Description
EVbee DC-80是EVbee公司的一款物联网设备。 EVbee DC-80 1.5.1之前版本存在输入验证错误漏洞,该漏洞源于对Content-Disposition标头中filename参数的输入验证不足,可用于通过覆盖系统文件导致拒绝服务,或通过覆盖可被其他方式触发的shell脚本导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A