Cicoandcico CcMail 1.0.1 及其早期版本并不会校验出this_cookie cookie相应的一个授权会话,远程攻击者通过一个修改的this_cookie cookie来获得"管理区域"的访问权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-1900 | carbon_communities option_Update.asp 设计错误漏洞 | |
| CVE-2008-1898 | Microsoft Works 7 WkImgSrv.dll ActiveX控件远程代码执行漏洞 | |
| CVE-2008-1436 | Microsoft Windows 权限许可和访问控制漏洞 | |
| CVE-2008-1694 | GNU Emacs创建不安全临时文件漏洞 | |
| CVE-2008-1679 | Python zlib模块远程溢出漏洞 | |
| CVE-2008-1613 | RedDot CMS ioRD.asp文件SQL注入漏洞 | |
| CVE-2008-1102 | Blender radiance_hdr.c文件远程栈溢出漏洞 | |
| CVE-2008-1902 | aptlinex GUI 设计错误漏洞 | |
| CVE-2008-1901 | Debian Aptlinex gambas-apt.lock 后置链接漏洞 | |
| CVE-2008-1903 | NewsOffice 'news_show.php'远程文件包含漏洞 | |
| CVE-2008-1911 | 1024 CMS 'includes/system.php' SQL注入漏洞 | |
| CVE-2008-1910 | Borland InterBase ibserver.exe服务远程缓冲区溢出漏洞 | |
| CVE-2008-1909 | PHPKB 'comment.php' SQL注入漏洞 | |
| CVE-2008-1908 | cpCommerce多个目录遍历漏洞 | |
| CVE-2008-1907 | cpCommerce functions/display_page.func.php 多个SQL注入漏洞 | |
| CVE-2008-1906 | cpCommerce calendar.php 跨站脚本攻击漏洞 | |
| CVE-2008-1905 | nero MediaHome 拒绝服务漏洞 |
No comments yet