Majordomo是一款开放源代码流行的邮件列表系统。 Majordomo没有充分处理好对订阅者列表信息的请求,远程攻击者可以利用这个漏洞发送特殊命令获得订阅者列表。 如果Majordomo配置文件中设置'which_access'选项为"open",那么所有邮件地址可以被攻击者获得。默认情况下,'which_access'设置为"open"。Majordomo有如下文档描述: "默认情况下,任何人(包含不是订阅者)可以使用"who", "which", "index", 和 "get"获得列表。如你在$
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2007-5490 | Okul Otomasyon Portal 'Default.ASP' SQL注入漏洞 | |
| CVE-2003-1373 | PHPBB Auth.PHP文件泄漏漏洞 | |
| CVE-2003-1372 | myPHPNuke Links.php跨站脚本漏洞 | |
| CVE-2003-1366 | OpenBSD CHPass不安全临时文件符号链接漏洞 | |
| CVE-2003-1370 | Nuked-Klan Guestbook HTML注入漏洞 | |
| CVE-2003-1369 | ByteCatcher FTP Client超长服务器标志缓冲区溢出漏洞 | |
| CVE-2003-1368 | Electrasoft 32Bit FTP Client超长服务器标语缓冲区溢出漏洞 | |
| CVE-2003-1371 | Nuked-Klan远程信息泄露漏洞 | |
| CVE-2003-1359 | HP-UX stmkfont未明本地缓冲区溢出漏洞 | |
| CVE-2003-1358 | HP-UX rs.F3000未明未授权访问漏洞 | |
| CVE-2003-1360 | HP-UX landiag/lanadmin本地缓冲区溢出漏洞 | |
| CVE-2007-5489 | Artmedic CMS 'Index.PHP' 本地文件包含漏洞 | |
| CVE-2007-5492 | SiteBar 翻译模块'translator.php' 静态代码注入漏洞 | |
| CVE-2007-5491 | SiteBar 翻译模块(translator.php)目录遍历漏洞 | |
| CVE-2007-5534 | Oracle PeopleSoft Enterprise和JD Edwards EnterpriseOne HCM组件未明远程攻击漏洞 | |
| CVE-2007-5533 | Oracle PeopleSoft Enterprise和JD Edwards EnterpriseOne People Tools组件安全漏洞 | |
| CVE-2007-5532 | Oracle PeopleSoft Enterprise和JD Edwards EnterpriseOne People Tools组件安全漏洞 | |
| CVE-2007-5531 | Oracle Help for Web 安全漏洞 | |
| CVE-2007-5530 | Oracle Database Enterprise Manager的Database Control组件未明影响和远程攻击漏洞 | |
| CVE-2007-5529 | Oracle E-Business Suite Self-Service Web应用程序组件未明远程攻击漏洞 |
Showing top 20 of 52 CVEs. View all on vendor page → →
No comments yet