Ingres是美国加利福尼亚大学柏克莱分校的一款数据库系统。 Ingres多个版本(Ingres 2.6, Ingres 2006 release1及release2 )中的ingvalidpw程序由于不可信的搜索路径而导致本地权限提升漏洞。在加载共享库时,ingvalidpw程序会加载用户目录中的库,本地用户可以通过特制的库获取特权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-3484 | eStoreAff index.php SQL注入漏洞 | |
| CVE-2008-3482 | Panasonic NetworkCamera 跨站脚本攻击漏洞 | |
| CVE-2008-3483 | ScrewTurn Software ScrewTurn Wiki 'System Log' Page HTML注入漏洞 | |
| CVE-2008-3356 | CA Ingres verifydb 本地权限提升漏洞 | |
| CVE-2008-3389 | CA Ingres libbecompat 栈溢出漏洞 | |
| CVE-2008-3431 | Sun xVM VirtualBox VBoxDrv.sys 本地权限提升漏洞 | |
| CVE-2008-3481 | CoppermineGallery CopperminePhotoGallery hemes/sample/theme.php 信息泄露漏洞 |
No comments yet