Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI
Vulnerability Description
ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply directory traversal sequences via the firmware parameter to access arbitrary files on the server, leading to information disclosure of sensitive system files.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
ZwickRoell Test Data Management 路径遍历漏洞
Vulnerability Description
ZwickRoell Test Data Management是日本ZwickRoell公司的一个测试数据管理系统。 ZwickRoell Test Data Management 3.0.8之前版本存在路径遍历漏洞,该漏洞源于/server/node_upgrade_srv.js端点存在本地文件包含漏洞,可能导致敏感系统文件信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A