TeamSpeak Server多个拒绝服务和绕过安全限制漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BUGTRAQ ID: 40918 TeamSpeak是一种专门为网络游戏玩家设计的IP语音通信系统。 TeamSpeak服务器在执行通过UDP 9987端口所接收到的受限制命令时没有要求认证,用户可以非授权执行各种管理命令。以下是部分有漏洞命令的列表: banclient bandel channeladdperm/channeldelperm channelclientaddperm/channelclientdelperm channeldelete channeledit channelmove clientaddperm/clientdelperm clientdbdelete clientget* clientkick clientmove clientpoke messageadd sendtextmessage serveredit servergroupadd setclientchannelgroup tokenadd/tokendel 此外通过UDP 9987端口发送以下命令还可以触发Assertion错误: banlist Assertion "invokerClientID != 0" failed at server\serverlib\virtualserver.cpp:7442; complainlist Assertion "client != 0" failed at server\serverlib\permission_manager.cpp:167; servernotifyunregister not implemented serverrequestconnectioninfo Assertion "client != 0" failed at server\serverlib\permission_manager.cpp:167; setconnectioninfo Assertion "clID != 0" failed at common\packethandler.cpp:367; servernotifyregister event=server not implemented 发送以下命令可触发空指针引用:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息