漏洞标题
D-Link DAR-8000-10 importhtml.php 反序列化
漏洞描述信息
**分配时不受支持** 在D-Link DAR-8000-10版本 up to 20230922中发现了一个被列为关键的漏洞。这个问题影响了文件/importhtml.php的某些未知处理。操纵参数sql导致反序列化。攻击可以远程发起。与该漏洞关联的标识符是VDB-263747。注意:此漏洞仅影响维护者不再支持的产品。注意:供应商已 early 联系并立即确认该产品已到生命周期结束。应退役并替换该产品。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
可信数据的反序列化
漏洞标题
D-Link DAR-8000-10 importhtml.php deserialization
漏洞描述信息
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-263747. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
可信数据的反序列化
漏洞标题
D-Link DAR-8000 代码问题漏洞
漏洞描述信息
D-Link DAR-8000是中国友讯(D-Link)公司的上网行为审计网关。 D-Link DAR-8000-10 20230922及之前版本存在代码问题漏洞,该漏洞源于文件/importhtml.php的参数sql会导致反序列化。
CVSS信息
N/A
漏洞类别
代码问题