漏洞标题
第七版 D-Guard HTTP GET 请求路径穿越漏洞
漏洞描述信息
在Seventh D-Guard版本20250206及之前版本中发现了一个分类为有问题的漏洞。该漏洞影响组件HTTP GET请求处理程序的未知部分。此漏洞可导致路径穿越。攻击者可以在远程发起攻击。漏洞的利用方法已被公开披露,并可能被利用。厂商已提前接到关于此漏洞的披露通知,但未对此作出任何回应。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
Seventh D-Guard HTTP GET Request path traversal
漏洞描述信息
A vulnerability classified as problematic has been found in Seventh D-Guard up to 20250206. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
对路径名的限制不恰当(路径遍历)