VULN REPORT
/
uzaktan
/
ID: 506
CVE-2026-47670 - DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
4.0
CVSS Severity Index
Medium Severity / Orta Seviye
Özet
Bu kayit, hedef sistemde bulunan CVE-2026-47670 zafiyetini detaylandirmaktadir. CRITICAL (CVSS 4) seviyesinde olan bu zafiyet Products surumlerini etkilemektedir. 29.07.2026 tarihinde yayinlanmistir. DbGate platformlar arası veritabanı yöneticisidir. 7.1.8 ve önceki sürümler, kimlik doğrulamalı Uzaktan Kod Yürütme (RCE) karşısında savunmasızdır. Geçerli DbGate kimlik bilgilerin...
exploit_506.txt
<div class="space-y-6 font-sans select-text text-left"><div class="bg-[#1C1C1E] border border-white/5 rounded-lg p-5"><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="info" class="w-3.5 h-3.5 text-[#26A269]"></i>Zafiyet Ozet Bilgileri</h3><div class="grid grid-cols-1 md:grid-cols-2 gap-4 text-sm"><div class="flex items-center gap-2"><span class="text-white/40">Zafiyet Kodu:</span><strong class="text-[#FF5F56] font-mono">CVE-2026-47670</strong></div><div class="flex items-center gap-2"><span class="text-white/40">Siddet Derecesi:</span><span class="font-bold font-mono" style="color:#FF5F56">CRITICAL</span></div><div class="flex items-center gap-2"><span class="text-white/40">CVSS Skoru:</span><span class="text-[#FFB800] font-bold font-mono">4</span></div><div class="flex items-center gap-2"><span class="text-white/40">Etkilenen Surumler:</span><span class="text-white/80 font-mono text-xs">Products</span></div><div class="flex items-center gap-2"><span class="text-white/40">Yayinlanma Tarihi:</span><span class="text-white/80 font-mono">29.07.2026</span></div></div></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="file-text" class="w-3.5 h-3.5 text-[#26A269]"></i>Zafiyet Detayı (Turkce)</h3><p class="text-white/70 leading-relaxed text-sm bg-[#1C1C1E]/30 p-4 border border-white/5 rounded-lg">DbGate platformlar arası veritabanı yöneticisidir. 7.1.8 ve önceki sürümler, kimlik doğrulamalı Uzaktan Kod Yürütme (RCE) karşısında savunmasızdır. Geçerli DbGate kimlik bilgilerine sahip herhangi bir kullanıcı, `/runners/load-reader` uç noktasındaki temizlenmemiş bir `functionName` parametresinden yararlanarak isteğe bağlı işletim sistemi komutlarını kök olarak çalıştırabilir. 'Require = null' azaltma, dinamik aracılığıyla önemsiz bir şekilde atlanır…</p></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="globe" class="w-3.5 h-3.5 text-[#26A269]"></i>Orijinal Aciklama (Ingilizce)</h3><p class="text-white/40 leading-relaxed text-xs bg-[#1C1C1E]/10 p-4 border border-white/5 rounded-lg italic">
CVE ID, Product, Vendor ...
Pricing
Browse by Apps
View All Apps
Splunk
Slack
Webhook
Teams
Jira
Chrome
API
</p></div><div><h3 class="text-xs font-bold text-white/50 mb-3 uppercase tracking-wider flex items-center gap-2"><i data-lucide="external-link" class="w-3.5 h-3.5 text-[#26A269]"></i>Referanslar</h3><div class="bg-[#1C1C1E]/10 p-4 border border-white/5 rounded-lg"><a href="https://cvefeed.io/vuln/detail/CVE-2026-47670" target="_blank" class="text-[#3b82f6] hover:underline font-mono text-xs break-all">https://cvefeed.io/vuln/detail/CVE-2026-47670</a></div></div><div class="border-t border-white/5 pt-4 flex justify-between items-center text-xs"><span class="text-white/30">Otomatik olarak RSS feed'inden ice aktarildi.</span><a href="https://cvefeed.io/vuln/detail/CVE-2026-47670" target="_blank" class="inline-flex items-center gap-1.5 text-[#26A269] hover:underline font-bold transition-all">Kaynagi Goruntule <i data-lucide="external-link" class="w-3.5 h-3.5"></i></a></div></div>
Kayıt İstatistikleri
Görüntülenme
4
İndirmeler
1
Yorumlar
0