VivaPrograms Infinity 2.0.5及之前版本中的cp/profile.php没有对donewauthor行为进行管理身份认证,这使得远程攻击者可以借助名字、密码和conf_password参数,创建管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-2746 | IBM WebSphere Application Server 跨站请求伪造漏洞 | |
| CVE-2009-3888 | Linux kernel 资源管理错误漏洞 | |
| CVE-2009-3889 | Linux kernel 权限许可和访问控制问题漏洞 | |
| CVE-2009-3939 | Linux Kernel "megaraid_sas" 驱动模式访问权限许可漏洞 | |
| CVE-2009-3940 | Sun xVM VirtualBox "Guest Additions" 未明拒绝服务攻击漏洞 | |
| CVE-2009-3941 | Martin Lambers mpop X.509证书加密问题漏洞 | |
| CVE-2009-3942 | Martin Lambers msmtp X.509证书加密问题漏洞 | |
| CVE-2009-3943 | Microsoft Internet Explorer 安全漏洞 | |
| CVE-2009-3944 | RIM BlackBerry 8800 RIM BlackBerry Browser JavaScript拒绝服务攻击漏洞 | |
| CVE-2009-3945 | Joomla! 组件"com_content" 未明漏洞 | |
| CVE-2009-3946 | Joomla! "XML"文件 信息泄露漏洞 | |
| CVE-2009-3947 | Tandberg MXP FTP服务缓冲区溢出漏洞 | |
| CVE-2009-3948 | JetAudio "COWON Media Center" 内存管理错误漏洞 | |
| CVE-2009-3950 | Bractus SunTrack 多个跨站脚本攻击漏洞 |
No comments yet