Gnut Gnutella Client Arbitrary...

- AV AC AU C I A
发布: 2001-08-30
修订: 2025-04-13

Gnut is a free, open-source console-based Gnutella file-sharing client for Microsoft Windows and Linux systems. A problem exists with Gnut's web interface. Webfrontend allows users to perform searches, but when the results of a search are returned the interface will not strip HTML tags from filenames. An attacker could exploit this issue by embedding script code in a filename, which will may be able to be run locally on the user when the file turns up in a search. This issue may allow the attacker to gain unauthorized access to resources on the system of the Gnut user.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息