Excel是微软Office套件中的电子表格工具。 如果用户使用Excel打开了畸形的.xls文档的话,就可能会引用无效的对象,导致以当前登录用户的权限执行任意代码。目前这个漏洞正在被名为Trojan.Mdropper.AC的木马积极的利用。当木马运行时,会在系统留下以下文件: %Temp%\rundll.exe 之后木马试图从以下位置下载更多的文件: [http://]61.59.24.55/sb.php?id=[19个随机ASCII字符] [http://]61.59.24.45/sb.php?id=
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-0506 | IBM WebSphere Application z/OS CSLv2 Identity Assertion 未明本地漏洞 | |
| CVE-2009-0737 | MediaWiki 'config/index.php' 多个跨站脚本攻击漏洞 | |
| CVE-2009-0738 | Frankmancuso Auth Php 'login.php' SQL注入漏洞 | |
| CVE-2009-0739 | Frankmancuso MyNews 'login.php' SQL注入漏洞 | |
| CVE-2009-0740 | Frankmancuso BlueBird Pre-release 'login.php' SQL注入漏洞 | |
| CVE-2009-0741 | Craft Silicon banking@0home 'Login.asp'SQL注入漏洞 | |
| CVE-2008-6272 | Miticdjd Dragan Mitic Apoll 'admin/index.php' SQL注入漏洞 | |
| CVE-2008-6273 | MyKtools 'configuration_script.php' 本地文件包含漏洞 | |
| CVE-2009-0505 | IBM TXSeries for Multiplatforms CICS应用程序服务器(CICSAS) 拒绝服务漏洞 | |
| CVE-2009-0736 | Simon Brown Pebble 未明向量跨站脚本攻击漏洞 | |
| CVE-2009-0540 | Insightinformatics Libero 'search term'跨站脚本攻击漏洞 | |
| CVE-2009-0541 | Magento Commerc多个跨站脚本攻击漏洞 | |
| CVE-2008-6266 | Appstate phpWebSite 'links.php' SQL注入漏洞 | |
| CVE-2008-6267 | Sadi_Samami Multi Languages WebShop Online 'detail.php'跨站脚本漏洞 | |
| CVE-2008-6268 | Sadi_Samami Multi Languages WebShop Online 'detail.php'SQL注入漏洞 | |
| CVE-2008-6269 | Joovili Cookie 权限绕过漏洞 | |
| CVE-2008-6270 | Miticdjd Dragan Mitic Apoll 'admin/index.php' SQL注入漏洞 | |
| CVE-2008-6271 | TBmnetCMS 'index.php' 目录遍历漏洞 | |
| CVE-2008-6283 | Subtextproject Subtext Anchor Tags HTML注入漏洞 | |
| CVE-2008-6275 | Drupal User Karma模块跨站脚本攻击漏洞 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet