Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
JD Cloud JDCOS Service jdcap set_iptv_info command injection
Vulnerability Description
A flaw has been found in JD Cloud JDCOS 4.5.1.r4518. This vulnerability affects the function set_iptv_info of the file /jdcap of the component Service Interface. Executing a manipulation of the argument vid can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
JD Cloud JDCOS 注入漏洞
Vulnerability Description
JD Cloud JDCOS是中国京东(JD)公司的一个云对象存储服务。 JD Cloud JDCOS 4.5.1.r4518版本存在注入漏洞,该漏洞源于组件Service Interface中文件/jdcap的函数set_iptv_info对参数vid的操作,可能导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A