Nessus LibNASL Arbitrary Code...

- AV AC AU C I A
发布: 2003-05-22
修订: 2025-04-13

Nessus has reported that various flaws have been discovered in the 'libnasl' library used by the Nessus application. As a result, a malicious NASL script may be able to break outside of the established sandbox environment and execute arbitrary commands on the local system. Note that this malicious script must be a legitimate plugin that has been uploaded to the Nessus server. Furthermore, the affected Nessus application must have enabled the 'plugins_upload' option (which is disabled by default).

0%
暂无可用Exp或PoC
当前有0条受影响产品信息