Sourcefire 3D Sensor和Defense Center都是流行的网络入侵保护系统 。 3D Sensor和Defense Center的web管理界面存在权限提升漏洞,允许任意本地账号获得设备的管理员角色。尽管user.cgi PERL脚本正确地验证了入站请求属于已认证的会话,在这种情况下没有考虑请求发起者的角色而盲目的给予了读写访问,因此即使是最低访问级别的用户(如没有配置任何角色的用户)也可以将其提升为管理员并随意更改其他角色或账号参数 。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-2340 | Opial damin/index.php SQL注入漏洞 | |
| CVE-2009-2338 | FreeWebshop startmodules.inc.php 本地权限限制漏洞 | |
| CVE-2009-2337 | w3bcms Guestbook Module 'index.inc.php' SQL注入漏洞 | |
| CVE-2008-6853 | NetCat 'modules/poll/index.php' SQL注入漏洞 | |
| CVE-2008-6852 | Joomla! Ice Gallery Component 'index.php' SQL注入漏洞 | |
| CVE-2008-6851 | PHP Link Directory 'page.php' SQL注入漏洞 | |
| CVE-2008-6850 | PHP-Fusion 'messages.php'跨站脚本漏洞 | |
| CVE-2008-6849 | W2B phpGreetCards 'index.php' 任意文件上传漏洞 | |
| CVE-2008-6848 | W2B phpGreetCards 'index.php' 跨站脚本漏洞 | |
| CVE-2009-2345 | ClanSphere gbook module 多个SQL注入漏洞 | |
| CVE-2009-2343 | Zoph 'people.php' 跨站脚本漏洞 | |
| CVE-2009-2342 | Content Management Made Easy admin.php跨站脚本攻击漏洞 | |
| CVE-2009-2341 | Shalwan Opial index.php SQL注入漏洞 | |
| CVE-2008-0015 | Microsoft DirectShow MPEG2TuneRequest 组件栈溢出漏洞 | |
| CVE-2009-2339 | rentventory index.php SQL注入漏洞 | |
| CVE-2009-2359 | Yasinkaplan TekRADIUS SQL注入漏洞 | |
| CVE-2009-2358 | Yasinkaplan TekRADIUS安全权限漏洞 | |
| CVE-2009-2357 | Yasinkaplan TekRADIUS RADIUS安全权限漏洞 | |
| CVE-2009-2356 | NullLogic Groupware pgSQLQuery函数缓冲区溢出安全漏洞 | |
| CVE-2009-2355 | Joomla!组件远程文件漏洞 |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet