漏洞描述 Bazarr 是 Sonarr 和 Radarr 的配套应用程序,可以根据您的要求管理和下载字幕。Bazaar v1.4.3中的static组件存在一个漏洞,未经验证的攻击者可以利用该漏洞执行目录遍历操作。
相关漏洞推荐 智联云采 SRM2.0 /adpweb/static/..;/a/db/dbBackupScheme/restore 命令执行漏洞 lsfusion /file/static/noauth 目录遍历漏洞(CVE-2025-13261) 智互联-SRM /adpweb/static/..;/api/authority/getUser 信息泄露漏洞 POC CVE-2024-40348: Bazarr < 1.4.3 - Arbitrary File Read POC CVE-2024-40348: Bazaar 任意文件读取漏洞 POC azure-storage-static-website-review: Azure Storage Static Website Configuration Review POC casdoor-static-fileread: Casdoor 任意文件读取漏洞 POC gcloud-nat-static-ip-unconfigured: Cloud NAT Gateways Not Configured with Reserved Static IPs POC gcloud-vpc-unattached-static-ips: Unattached Static External IP Addresses POC gstatic-angular-csp-bypass: Content-Security-Policy Bypass - GStatic Angular POC gstatic-recaptcha-csp-bypass: Content-Security-Policy Bypass - GStatic reCAPTCHA POC gstatic-ssl-csp-bypass: Content-Security-Policy Bypass - GStatic SSL POC parastorage-static-csp-bypass: Content-Security-Policy Bypass - Parastorage Static