DragonFly Public - Signup Enabled
Dragonfly public registration is enabled was discovered.
PoC 已收录dragonfly
CVSS—
共找到 3 条公开漏洞记录
Dragonfly public registration is enabled was discovered.
Ruby Dragonfly before 1.4.0 contains an argument injection vulnerability that allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
Dragonfly was using the default username, and the password was discovered.