漏洞标题
N/A
漏洞描述信息
这个漏洞允许远程攻击者泄露NetGain Systems Enterprise Manager 7.2.699 build 1001中脆弱性安装的敏感信息。尽管要利用这个漏洞需要验证身份,但现有的身份验证机制可以被绕过。这个特定漏洞存在于org.apache.jsp.u.jsp.restore.download_005fdo_jspservlet中,它默认 listens on TCP port 8081。在解析文件名参数时,程序在用户使用它在文件操作中使用之前未正确验证用户提供的路径。攻击者可以利用此漏洞与其他漏洞结合来在管理员上下文中执行代码。 Was ZDI-CAN-5100。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.restore.download_005fdo_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of Administrator. Was ZDI-CAN-5100.
CVSS信息
N/A
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
NetGain Enterprise Manager 信息泄露漏洞
漏洞描述信息
Netgain Enterprise Manager(EM)是新加坡网利系统(NetGain Systems)公司的一套IT资产监控管理软件。 NetGain Enterprise Manager 7.2.699 build 1001版本中的org.apache.jsp.u.jsp.restore.download_005fdo_jsp servlet存在信息泄露漏洞,该漏洞源于进程在执行文件操作之前,没有正确的验证用户提交的路径。远程攻击者可利用该漏洞泄露敏感信息。
CVSS信息
N/A
漏洞类别
信息泄露