Citrix Presentation Server允许用户通过网络远程访问应用程序。 Citrix Presentation Server处理用户请求时存在漏洞,远程攻击者可能利用此漏洞控制服务器。 Citrix Presentation Server中默认监听于TCP 2512或2513端口上的的独立管理架构服务(ImaSrv.exe),错误的信任了用户提供的值作为内存拷贝的参数,如果提供了特殊的值的话就可能导致分配不足的堆缓冲区,然后攻击者就可以通过发送超长报文来触发溢出,导致以系统权限执行任意指令
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-0366 | CORE FORCE Registry Modules 多个本地内核缓冲区溢出漏洞 | |
| CVE-2008-0363 | Clever Copy 'postcomment.php'和'gallery.php'多个 SQL注入漏洞 | |
| CVE-2008-0362 | Clever Copy Multiple 'gallery.php' 跨站脚本漏洞 | |
| CVE-2008-0361 | GradMan 'agregar_info.php'目录遍历漏洞 | |
| CVE-2008-0360 | BLOG:CMS 多个SQL注入漏洞 | |
| CVE-2008-0359 | BLOG:CMS 'admin.php和photo/index.php'跨站脚本漏洞 | |
| CVE-2008-0358 | Pixelpost 'index.php' SQL注入漏洞 | |
| CVE-2008-0357 | GalaxyScripts Mini File Host 'upload.php'目录遍历漏洞 | |
| CVE-2008-0355 | PHPEcho CMS 'index.php' SQL注入漏洞 | |
| CVE-2008-0354 | IBM Lotus Sametime 跨站脚本漏洞 | |
| CVE-2008-0353 | php-residence 'visualizza_tabelle.php'SQL注入漏洞 | |
| CVE-2008-0367 | Firefox "Basic Realm"基础认证头欺骗漏洞 | |
| CVE-2008-0365 | CORE FORCE Firewall and Registry Modules 本地内核缓冲区溢出漏洞 | |
| CVE-2008-0364 | BitTorrent和uTorrent Peers窗口缓冲区溢出漏洞 | |
| CVE-2008-0006 | X.Org X Server PCF字体解析器缓冲区溢出漏洞 | |
| CVE-2007-6429 | X.Org X Server MIT-SHM及EVI扩展整数溢出漏洞 | |
| CVE-2007-6428 | X.Org X Server TOG-CUP扩展内存泄露漏洞 | |
| CVE-2007-6427 | X.Org X Server 缓冲区错误漏洞 | |
| CVE-2007-5958 | X.Org X Server "X:1 -sp"命令 信息泄露漏洞 | |
| CVE-2007-5760 | X.Org X Server XFree86-Misc扩展无效数组索引漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet