漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
Vulnerability Description
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
VITEC Flamingo 命令注入漏洞
Vulnerability Description
VITEC Flamingo是法国VITEC公司的一家全球领先的 IP 视频流解决方案提供商,专注于企业 IPTV、数字标牌和视频流媒体技术,帮助企业通过视频进行通信、教育和娱乐。 VITEC Flamingo 4.12.2版本存在命令注入漏洞,该漏洞源于在admin/ajax/gen_graphs.php端点中,用户提供的start、end、key、format HTTP GET参数未进行输入清理,直接通过passthru()函数传递给shell命令,可能导致未经身份验证的远程攻击者通过shell元字符
CVSS Information
N/A
Vulnerability Type
N/A