Adobe Acrobat和Reader都是非常流行的PDF文件阅读器。 Adobe Acrobat和Reader没有正确地处理PDF文档中所包含的恶意JavaScript。如果向Collab对象的getIcon()方式提供了特制参数,就可以触发栈溢出。成功利用这个漏洞允许以当前登录用户的权限完全控制受影响的机器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-6489 | Joomla!和Mambo MyAlbum组件'index.php' SQL注入漏洞 | |
| CVE-2008-6490 | FlysForum FLABER r’function/update_xml.php’ 输入验证错误漏洞 | |
| CVE-2008-6491 | PhpGKit 'connexion.php' 远程文件包含漏洞 | |
| CVE-2009-0661 | Flashtux WeeChat IRC消息远程拒绝服务漏洞 | |
| CVE-2009-0963 | Xlinesoft PHPRunner 多个脚本SearchField参数SQL注入漏洞 | |
| CVE-2009-0964 | Xlinesoft PHPRunner 脚本UserView_list.php SQL注入漏洞 | |
| CVE-2009-0965 | GDL 'functions/browse.ph' SQL注入漏洞 | |
| CVE-2009-0966 | Yabsoft Mega File Hosting Script 'cross.php'远程文件包含漏洞 | |
| CVE-2009-0967 | SolarWinds Serv-U File Server 资源管理错误漏洞 | |
| CVE-2009-0968 | WordPress fMoblog插件id参数SQL注入漏洞 | |
| CVE-2009-0969 | phpFoX 'account/settings/account/index.php'跨站请求伪造漏洞 | |
| CVE-2009-0970 | PHP Pro Bid 'includes/class_image.php'代码注入漏洞 | |
| CVE-2009-0971 | Futomi Access Analyzer CGI跨站脚本攻击漏洞 | |
| CVE-2009-0962 | Futomi's CGI Cafe MP Form Mail CGI 未明安全绕过漏洞 |
No comments yet