ActiveCampaign SupportTrio 2.5可以让远程攻击者通过以下途径获取服务器完整路径:无效的 (1) article或(2)用于index.php中的kb操作print参数,(3)一个用于modules/KB/pdf.php中的无效category参数,它会在一条出错短信中暴露路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2006-1475 | Microsoft Windows XP Windows防火墙NTFS Alternate Data Streams木马攻击漏洞 | |
| CVE-2006-1485 | Noah Grey Greymatter 'gm-upload.cgi'任意文件上载漏洞 | |
| CVE-2006-1484 | Genius VideoCAM NB本地特权升级漏洞 | |
| CVE-2006-1483 | Blazix Java Application/Web Server JSP源码泄露漏洞 | |
| CVE-2006-1482 | ConfTool 'Index.PHP'跨站脚本攻击漏洞 | |
| CVE-2006-1481 | PHP Ticket 'Search.PHP' SQL注入漏洞 | |
| CVE-2006-1480 | WEBalbum远程命令执行漏洞 | |
| CVE-2006-1479 | GTD-PHP多个输入验证漏洞 | |
| CVE-2006-1478 | Turnkey Web Tools PHP Live Helper 'initiate.php'目录遍历漏洞 | |
| CVE-2006-1477 | PHP Live Helper 'Initiate.PHP'远程文件包含漏洞 | |
| CVE-2006-1476 | Microsoft Windows XP 防火墙".exe"文件诱导恶意文件漏洞 | |
| CVE-2006-0459 | Flex 缓冲区错误漏洞 | |
| CVE-2006-1474 | Raindance Web Conferencing Pro "failed"函数跨站脚本攻击(XSS)漏洞 | |
| CVE-1999-1587 | Sun Microsystems Solaris /usr/ucb/ps变量值任意查看漏洞 | |
| CVE-2006-1487 | ActiveCampaign KnowledgeBase搜索模块不明参数跨站脚本攻击漏洞 | |
| CVE-2006-1486 | RealestateZONE ‘index.cfm’跨站脚本攻击漏洞 | |
| CVE-2006-1489 | FusionZONE CouponZONE多个SQL注入漏洞 | |
| CVE-2006-1490 | PHP 安全漏洞 | |
| CVE-2006-1493 | Explorer 'dir.php'跨站脚本攻击(XSS)漏洞 | |
| CVE-2006-1492 | Explorer XP ‘dir.php’目录遍历漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet