漏洞标题
更新文件目录路径的遍历允许无授权的任意文件读取漏洞
漏洞描述信息
更新文件目录路径遍历允许未验证的任意文件读取漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
updateFile Directory Path Traversal Allows Unauthenticated Arbitrary File Read Vulnerability
漏洞描述信息
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the current user.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
LG LED Assistant 路径遍历漏洞
漏洞描述信息
LG LED Assistant是韩国乐金(LG)公司的一个软件。用于设置 LED 灯。 LG LED Assistant存在安全漏洞,该漏洞源于在文件操作中使用用户提供的路径之前未对其进行正确验证,允许远程攻击者泄露当前用户上下文中的信息。
CVSS信息
N/A
漏洞类别
路径遍历